Extension WordPress

Vulnérabilités Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Cette page rassemble les failles publiées pour Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported), leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
2Critiques
8Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

8 fiches

CVE-2026-57412 Moyenne · 5,3
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.6.9 – Missing Authorization

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.9. This makes it possible for…

Versions affectées

*-4.6.9

Correctif

4.7.0

Publication

08/07/2026

CVE-2026-57415 Élevée · 7,2
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.7.0 – Unauthenticated Stored Cross-Site Scripting

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-4.7.0

Correctif

4.7.1

Publication

08/07/2026

CVE-2024-13520 Moyenne · 5,3
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.9 – Missing Authorization to Unauthenticated Price, Date, and Note Updates

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to,…

Versions affectées

*-4.4.9

Correctif

4.5.0

Publication

19/02/2025

CVE-2024-9165 Moyenne · 6,4
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.4 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping.…

Versions affectées

*-4.4.4

Correctif

4.4.5

Publication

30/10/2024

CVE-2024-32436 Moyenne · 4,3
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Vouchers <= 4.4.0 – Cross-Site Request Forgery

The Gift Vouchers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on the create_default_pages function. This makes it possible for unauthenticated…

Versions affectées

*-4.4.0

Correctif

4.4.1

Publication

12/04/2024

Vulnérabilité Moyenne · 4,3
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Cards (Gift Vouchers and Packages) <= 4.3.5 – Cross-Site Request Forgery in new_voucher_template.php

The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.5. This is due to missing or incorrect nonce validation within new_voucher_template.php. This makes it possible…

Versions affectées

*-4.3.5

Correctif

4.3.6

Publication

07/07/2023

CVE-2023-28662 Critique · 9,8
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)

Gift Cards (Gift Vouchers and Packages) <= 4.3.2 – Unauthenticated SQL Injection

The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to SQL Injection via the 'template' parameter of the wpgv_doajax_voucher_pdf_save_func AJAX action in versions up to, and including, 4.3.2 due to insufficient escaping on the user…

Versions affectées

*-4.3.2

Correctif

4.3.3

Publication

29/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités