Extension WordPress
Vulnérabilités Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Cette page rassemble les failles publiées pour Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
8 fiches
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.6.9 – Missing Authorization
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.9. This makes it possible for…
*-4.6.9
4.7.0
08/07/2026
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.7.0 – Unauthenticated Stored Cross-Site Scripting
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.7.0
4.7.1
08/07/2026
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.9 – Missing Authorization to Unauthenticated Price, Date, and Note Updates
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to,…
*-4.4.9
4.5.0
19/02/2025
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.4 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping.…
*-4.4.4
4.4.5
30/10/2024
Gift Vouchers <= 4.4.0 – Cross-Site Request Forgery
The Gift Vouchers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on the create_default_pages function. This makes it possible for unauthenticated…
*-4.4.0
4.4.1
12/04/2024
Gift Cards (Gift Vouchers and Packages) <= 4.3.5 – Cross-Site Request Forgery in new_voucher_template.php
The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.5. This is due to missing or incorrect nonce validation within new_voucher_template.php. This makes it possible…
*-4.3.5
4.3.6
07/07/2023
Gift Cards (Gift Vouchers and Packages) <= 4.3.2 – Unauthenticated SQL Injection
The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to SQL Injection via the 'template' parameter of the wpgv_doajax_voucher_pdf_save_func AJAX action in versions up to, and including, 4.3.2 due to insufficient escaping on the user…
*-4.3.2
4.3.3
29/03/2023
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) < 4.1.8 – SQL Injection
The Gift Vouchers plugin before 4.1.8 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
[*, 4.1.8)
4.1.8
26/08/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.