Junglewise Threat Intelligence

CVE-2026-54809: VillaTheme GIFT4U Blind SQL injection

CVE-2026-54809 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Vendors: VillaTheme.

Executive brief

VillaTheme GIFT4U, a WordPress plugin used for managing gift cards in WooCommerce stores, contains a critical security flaw. An attacker can use this vulnerability to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information or disruption of store operations.

Technical details

A Blind SQL Injection vulnerability exists in the VillaTheme GIFT4U plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw allows an unauthenticated remote attacker to execute arbitrary SQL queries against the underlying database by sending specially crafted web requests. Because it is a 'blind' injection, attackers can infer data by observing differences in server responses or timing. This can result in full unauthorized access to sensitive database records. The issue is resolved in version 1.1.0.

Affected products

  • VillaTheme GIFT4U - Gift Cards All In One For Woo up to 1.0.10

Timeline

  • 2026-02-26: other: Reported by researcher Ali Osman ERBAS
  • 2026-06-17: disclosed: Vulnerability published by Patchstack and NVD
  • 2026-06-17: patched: Version 1.1.0 released to address the vulnerability

References