Codemenschen Gift Cards vulnerabilities
2 known vulnerabilities affecting codemenschen/gift_cards.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-9165P4MEDIUMCVSS 6.4≤ 4.4.42024-10-31
CVE-2024-9165 [MEDIUM] CWE-79 CVE-2024-9165: The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerab
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inje
nvd
CVE-2024-13520P4MEDIUMCVSS 5.3≤ 4.4.92025-02-20
CVE-2024-13520 [MEDIUM] CWE-862 CVE-2024-13520: The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerab
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.9. This makes it possible for unauth
nvd