MEDIUM
Josh Kohlbach
CVE published 2026-04-08
CVE-2026-39508
The Advanced Coupons for WooCommerce Coupons plugin has a DOM-Based XSS vulnerability due to improper neutralization of input during web page generation. This issue affects versions from n/a through <= 4.7.1.1. The vulnerability has a CVSS score of 6.5 and is considered Medium priority. Users of the plugin should review and apply updates to prevent potential exploitation.