Executive brief
GIFT4U is a WordPress plugin used by e-commerce sites to manage gift cards within WooCommerce. A security flaw allows unauthenticated users to perform actions they should not have permission for, potentially interfering with gift card management or site operations. This could lead to unauthorized changes to gift card data or minor service disruptions.
Technical details
The GIFT4U plugin for WordPress (versions <= 1.0.10) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions that should be restricted to higher-privileged users. The vulnerability is rated with a CVSS 3.1 score of 6.5, indicating impact on integrity and availability without requiring user interaction or special privileges. The issue is resolved in version 1.1.0.
Affected products
- VillaTheme GIFT4U - Gift Cards All In One For Woo <= 1.0.10
Timeline
- 2026-02-26: other: Reported by researcher Ali Osman ERBAS
- 2026-06-26: disclosed: Vulnerability published by Patchstack
- 2026-06-26: patched: Version 1.1.0 released to address the issue