The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shops coupon codes and values via GraphQL.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Wpgraphql |
Wpengine |
* |
0.12.3 (including) |
References