plugin

Yith Woocommerce Gift Cards Premium Vulnerabilities

5 known security issues reported for the Yith Woocommerce Gift Cards Premium WordPress plugin. Most recent disclosed Mar 21, 2024.

2 critical 1 medium

Running Yith Woocommerce Gift Cards Premium on your site? Check whether your installed version is affected.

Scan your site free

YITH WooCommerce Gift Cards Premium [yith-woocommerce-gift-cards-premium] < 3.24.0

unknown

[en] Missing Authorization vulnerability in YITH YITH WooCommerce Gift Cards Premium.This issue affects YITH WooCommerce Gift Cards Premium: from n/a through 3.23.1.

Affected:
up to 3.24.0
Fixed in:
3.24.0
Disclosed:
Mar 21, 2024

CVE-2022-44633 on NVD →

YITH WooCommerce Gift Cards Premium <= 3.23.1 - Missing Authorization

medium

The YITH WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to unauthorized gift card creation due to a missing capability check on one of its functions in versions up to, and including, 3.23.1. This makes it possible for unauthenticated attackers to create gift cards. Sanitization of user input is also...

CVSS:
6.5
Affected:
up to 3.23.1
Fixed in:
3.24.0
Disclosed:
May 10, 2023

CVE-2022-44633 on NVD →

YITH WooCommerce Gift Cards Premium [yith-woocommerce-gift-cards-premium] < 3.20.0

unknown

[en] Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.

Affected:
up to 3.20.0
Fixed in:
3.20.0
Disclosed:
Dec 6, 2022

CVE-2022-45359 on NVD →

Yith WooCommerce Gift Cards Premium <= 3.19.0 - Unauthenticated Arbitrary File Upload

critical

The Yith WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the import_actions_from_settings_panel function in versions up to, and including, 3.19.0. This makes it possible for unauthenticated attackers to upload arbit...

CVSS:
9.8
Affected:
up to 3.19.0
Fixed in:
3.20.0
Disclosed:
Nov 22, 2022

CVE-2022-45359 on NVD →

YITH WooCommerce Gift Cards Premium <= 3.3.0 - Arbitrary File Upload

critical

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a vali...

CVSS:
9.8
Affected:
up to 3.3.1
Fixed in:
3.3.1
Disclosed:
Jan 27, 2021

CVE-2021-3120 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database