plugin

Gift Voucher Vulnerabilities

15 known security issues reported for the Gift Voucher WordPress plugin. Most recent disclosed Jul 8, 2026.

2 critical 1 high 5 medium

Running Gift Voucher on your site? Check whether your installed version is affected.

Scan your site free

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.7.0 - Unauthenticated Stored Cross-Site Scripting

high

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
7.2
Affected:
up to 4.7.0
Fixed in:
4.7.1
Disclosed:
Jul 8, 2026

CVE-2026-57415 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.6.9 - Missing Authorization

medium

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.6.9
Fixed in:
4.7.0
Disclosed:
Jul 8, 2026

CVE-2026-57412 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.5.0

unknown

[en] The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4....

Affected:
up to 4.5.0
Fixed in:
4.5.0
Disclosed:
Feb 20, 2025

CVE-2024-13520 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.9 - Missing Authorization to Unauthenticated Price, Date, and Note Updates

medium

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.9. Th...

CVSS:
5.3
Affected:
up to 4.4.9
Fixed in:
4.5.0
Disclosed:
Feb 19, 2025

CVE-2024-13520 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.4.5

unknown

[en] The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Affected:
up to 4.4.5
Fixed in:
4.4.5
Disclosed:
Oct 31, 2024

CVE-2024-9165 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Auth...

CVSS:
6.4
Affected:
up to 4.4.4
Fixed in:
4.4.5
Disclosed:
Oct 30, 2024

CVE-2024-9165 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.4.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Codemenschen Gift Vouchers.This issue affects Gift Vouchers: from n/a through 4.4.0.

Affected:
up to 4.4.1
Fixed in:
4.4.1
Disclosed:
Apr 15, 2024

CVE-2024-32436 on NVD →

Gift Vouchers <= 4.4.0 - Cross-Site Request Forgery

medium

The Gift Vouchers plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on the create_default_pages function. This makes it possible for unauthenticated attackers to trigger the creation of default pages via a forge...

CVSS:
4.3
Affected:
up to 4.4.0
Fixed in:
4.4.1
Disclosed:
Apr 12, 2024

CVE-2024-32436 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.3.6

unknown

Update the WordPress Gift Vouchers plugin to the latest available version (at least 4.3.6). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Gift Vouchers Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their...

Affected:
up to 4.3.6
Fixed in:
4.3.6
Disclosed:
Jul 11, 2023

Gift Cards (Gift Vouchers and Packages) <= 4.3.5 - Cross-Site Request Forgery in new_voucher_template.php

medium

The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.5. This is due to missing or incorrect nonce validation within new_voucher_template.php. This makes it possible for unauthenticated attackers to create new voucher templates...

CVSS:
4.3
Affected:
up to 4.3.5
Fixed in:
4.3.6
Disclosed:
Jul 7, 2023

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.3.6

unknown

The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.5. This is due to missing or incorrect nonce validation within new_voucher_template.php. This makes it possible for unauthenticated attackers to create new voucher templates...

Affected:
up to 4.3.6
Fixed in:
4.3.6
Disclosed:
Jul 7, 2023

Gift Cards (Gift Vouchers and Packages) <= 4.3.2 - Unauthenticated SQL Injection

critical

The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to SQL Injection via the 'template' parameter of the wpgv_doajax_voucher_pdf_save_func AJAX action in versions up to, and including, 4.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

CVSS:
9.8
Affected:
up to 4.3.2
Fixed in:
4.3.3
Disclosed:
Mar 29, 2023

CVE-2023-28662 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.3.3

unknown

[en] The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

Affected:
up to 4.3.3
Fixed in:
4.3.3
Disclosed:
Mar 22, 2023

CVE-2023-28662 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) [gift-voucher] < 4.1.8

unknown

[en] The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Aug 30, 2018

CVE-2018-16159 on NVD →

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) < 4.1.8 - SQL Injection

critical

The Gift Vouchers plugin before 4.1.8 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

CVSS:
9.8
Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Aug 26, 2018

CVE-2018-16159 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database