CVE-2026-91020

⚪ Do wiadomości

Brak walidacji kwoty karty podarunkowej w pluginie WooCommerce pozwala na manipulację ceną zamówienia.

CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-10-02 07:16:38 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:00:34 UTC
Referencje