Coupon API
Coupon API has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 4.9 out of 10.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for Coupon API has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Jonas Benjamin Friedli. Coupon API is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-8692Coupon API <= 6.2.12 - Authenticated (Administrator+) SQL Injection via 'log_duration'
Read the full analysisVulnerability Records

Coupon API
Author
Kamil Khan
Automatically import Coupons & Deals from popular Affiliate Networks into your WordPress Coupon Website. Features Get Coupons & Deals from popular Affiliate Networks Automatically updates your Website with new/modified/deleted offers in every 1 Hour No revenue sharing. Adds YOUR Affiliate IDs to all Landing Page URLs Map names of Stores & Categories as per your website Option to manually bulk-import your own Coupons & Deals Supported Themes ClipMyDeals Coupon + Cashback Theme Rehub (ReDeal Child Theme) CouponXL CouponXXL CouponWP Couponer Couponis Coupon by MyThemeShop PremiumPress Clipper CouponHut CouponMart WP-Coupon-Pro CouponPress by Coupon Themes All WordPress Themes Disclaimer This plugin makes API calls to CouponAPI.org. It uses your API Key to fetch the latest coupons & deals. Please visit CouponAPI.org to understand the details of all Features. Also read the Privacy Policy and Terms of Use carefully. Support In case of queries, drop an email to help@couponapi.org
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C