The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6. This makes it possible for unauthenticated attackers to update the value, expiration date, and user note for any gift voucher.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codemenschen
Codemenschen gift Vouchers |
|
CPEs | cpe:2.3:a:codemenschen:gift_vouchers:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Codemenschen
Codemenschen gift Vouchers |
Thu, 20 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Feb 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6. This makes it possible for unauthenticated attackers to update the value, expiration date, and user note for any gift voucher. | |
Title | Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.6 - Missing Authorization to Unauthenticated Price, Date, and Note Updates | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-20T09:21:36.119Z
Updated: 2025-02-20T14:26:57.528Z
Reserved: 2025-01-17T18:51:52.140Z
Link: CVE-2024-13520

Updated: 2025-02-20T14:26:53.645Z

Status : Analyzed
Published: 2025-02-20T10:15:10.167
Modified: 2025-02-25T20:55:11.400
Link: CVE-2024-13520

No data.