PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40770 RelyWP CVE debrief

CVE-2026-40770 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Coupon Affiliates plugin versions <= 7.5.3. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-40770).

Vendor
RelyWP
Product
Coupon Affiliates
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of Coupon Affiliates plugin versions <= 7.5.3 should apply patches or mitigations to prevent exploitation.

Technical summary

The vulnerability is caused by a lack of proper input validation and sanitization in the Coupon Affiliates plugin, allowing an unauthenticated attacker to inject malicious JavaScript code.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches or updates to Coupon Affiliates plugin versions <= 7.5.3.
  • Implement additional security measures such as input validation and sanitization.

Evidence notes

Evidence of this vulnerability was provided by Patchstack.

Official resources

CVE-2026-40770 was published on 2026-06-15T21:16:49.597Z and modified on 2026-06-15T21:24:32.790Z.