The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shops coupon codes and values via GraphQL.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Wpgraphql | Wpengine | * | 0.12.3 (including) |
References