CVE-2024-13520
20.02.2025, 10:15
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6. This makes it possible for unauthenticated attackers to update the value, expiration date, and user note for any gift voucher.Enginsight
Vendor | Product | Version |
---|---|---|
codemenschen | gift_vouchers | 𝑥 ≤ 4.4.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References