CVE-2022-1563

CVE-2022-1563: WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure

Vendor Unknown
Product wp-graphql-woocommerce
Published January 16, 2024
Last update June 20, 2025

CVSS base score

What the vulnerability does

01Description

The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL.

Key dates

02Disclosure timeline

January 16, 2024 CVE published
June 20, 2025 Record updated