CVE-2024-13316 Details
Description
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the apmswn_create_discount() function in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to create coupons.
A vulnerability exists in the Scratch & Win – Giveaways and Contests plugin for WordPress, in versions through 2.8.0. The issue arises from a lack of proper capability checks in the apmswn_create_discount() function, allowing unauthenticated users to create coupons. This unauthorized access could be exploited to generate discount codes without any verification or authentication.
Users are advised to update the Scratch & Win – Giveaways and Contests plugin to version 2.9.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| akashmalik scratch & win | < 2.9.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | Reanalysis | [email protected] |
| Feb 21, 2025 | Initial Analysis | [email protected] |
| Feb 18, 2025 | New CVE Received | [email protected] |