CVE-2026-91020
⚪ Do wiadomości
Brak walidacji kwoty karty podarunkowej w pluginie WooCommerce pozwala na manipulację ceną zamówienia.
CVSS
5.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-10-02 07:16:38 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:00:34 UTC |