Vulnerabilities
Vulnerable Software
Codemenschen:  >> Gift Vouchers  Security Vulnerabilities
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6. This makes it possible for unauthenticated attackers to update the value, expiration date, and user note for any gift voucher.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-02-20
The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.
CVSS Score
9.8
EPSS Score
0.683
Published
2023-03-22
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
CVSS Score
9.8
EPSS Score
0.664
Published
2018-08-30


Contact Us

Shodan ® - All rights reserved