The Coupon Creator plugin for WordPress is vulnerable to a security issue called Cross-Site Request Forgery. This affects versions of the plugin up to 3.1 and occurs because of missing or incorrect validation when the save_meta() function is used. This could potentially allow unauthenticated attackers to save meta fields if the site administrator were tricked into clicking on a link.