← Back

Woocommerce Multiple Free Gift

woocommerce_multiple_free_gift

Vendor: Lilmonkee • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lilmonkee
1Woocommerce Multiple Free Gift
Sep 27, 2024
Sep 14, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be a...Show more
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.Show less