Skip to main content

CVE-2025-8692: WordPress Coupon API Plugin SQLi Vulnerability

CVE-2025-8692 is a SQL injection flaw in the WordPress Coupon API plugin affecting versions up to 6.2.12. Authenticated administrators can extract sensitive database information. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-8692 Overview

CVE-2025-8692 is a SQL Injection vulnerability in the Coupon API plugin for WordPress. The flaw affects all versions up to and including 6.2.12. The vulnerability stems from insufficient escaping of the log_duration parameter and lack of proper preparation on the existing SQL query. Authenticated attackers with Administrator-level access or above can append additional SQL queries to existing ones. Successful exploitation allows extraction of sensitive data from the WordPress database. The weakness is classified as [CWE-89] Improper Neutralization of Special Elements used in an SQL Command.

Critical Impact

Authenticated administrators can inject arbitrary SQL through the log_duration parameter to read sensitive data from the WordPress database.

Affected Products

  • Coupon API plugin for WordPress, all versions up to and including 6.2.12
  • WordPress sites with the Coupon API plugin installed and activated
  • Multi-site WordPress deployments where the plugin is network-enabled

Discovery Timeline

  • 2025-09-11 - CVE-2025-8692 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-8692

Vulnerability Analysis

The Coupon API plugin exposes administrative functionality that logs coupon activity over a configurable duration. The log_duration parameter is passed into a SQL statement without adequate sanitization or parameterization. Attackers with Administrator privileges can craft log_duration values that break out of the original query context and append additional SQL clauses. This allows data extraction from any table the WordPress database user can access, including wp_users and wp_usermeta. Because exploitation requires Administrator-level authentication, the practical risk is elevated in multi-admin environments, shared hosting scenarios, and cases where administrator credentials have been compromised through phishing or credential reuse.

Root Cause

The vulnerable code paths reside in views.php of the plugin, specifically at lines 530, 559, and 577 of the plugin trunk. Each location concatenates the log_duration value directly into a SQL string rather than using the wpdb->prepare() API with placeholder binding. The plugin also fails to cast the parameter to an integer or validate it against an allow-list of expected values.

Attack Vector

An authenticated administrator submits a crafted log_duration value to the plugin endpoint that processes coupon log queries. The injected SQL is concatenated into the query and executed against the WordPress database. Extracted results can be returned in the response or exfiltrated through blind or time-based techniques. The vulnerability is network-reachable and requires no user interaction beyond the attacker's own authenticated session.

The vulnerability manifests in the coupon log query construction. See the Wordfence Vulnerability Report and the WordPress Plugin Code Reference Line 530 for technical details.

Detection Methods for CVE-2025-8692

Indicators of Compromise

  • Unexpected values in the log_duration request parameter containing SQL keywords such as UNION, SELECT, SLEEP, or --
  • Web server access logs showing repeated requests to the Coupon API plugin endpoints from administrator sessions
  • Database error entries in the PHP or MySQL error log referencing malformed queries originating from views.php
  • Unusual outbound traffic or oversized responses from wp-admin pages associated with the plugin

Detection Strategies

  • Deploy a Web Application Firewall (WAF) rule that inspects the log_duration parameter for non-numeric or SQL metacharacter content
  • Enable MySQL general query logging in test environments to identify unbounded queries generated by the Coupon API plugin
  • Monitor WordPress audit logs for administrator accounts performing atypical activity against plugin endpoints
  • Correlate authentication events with plugin request patterns to identify compromised administrator credentials

Monitoring Recommendations

  • Alert on any HTTP request where log_duration contains characters other than digits
  • Track query volume and response size for Coupon API endpoints to detect data extraction attempts
  • Review administrator account inventory and remove dormant or unnecessary privileged accounts

How to Mitigate CVE-2025-8692

Immediate Actions Required

  • Update the Coupon API plugin to a version newer than 6.2.12 as soon as a fixed release is available from the vendor
  • Deactivate and remove the Coupon API plugin if it is not actively used in production
  • Rotate WordPress administrator credentials and enforce multi-factor authentication on all privileged accounts
  • Review database access logs for evidence of unauthorized queries targeting wp_users or other sensitive tables

Patch Information

At the time of publication, the NVD entry references the vulnerable code in views.php at lines 530, 559, and 577. Administrators should consult the Wordfence Vulnerability Report and the plugin's official WordPress.org listing for the current fixed version. Apply the patched release across all environments once available.

Workarounds

  • Restrict access to the WordPress admin interface by IP allow-list at the web server or reverse proxy layer
  • Apply a WAF rule that rejects requests where log_duration is non-numeric before they reach WordPress
  • Reduce the number of administrator accounts and audit remaining accounts for necessity
  • Enforce database least-privilege by granting the WordPress database user only the tables and operations required by the site
bash
# Example ModSecurity rule to block non-numeric log_duration values
SecRule ARGS:log_duration "!@rx ^[0-9]+$" \
    "id:1008692,phase:2,deny,status:403,\
    msg:'CVE-2025-8692 Coupon API SQLi attempt in log_duration'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.