Junglewise Threat Intelligence

CVE-2026-57396: Flintop Free Gifts for WooCommerce Stored XSS

CVE-2026-57396 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

A vulnerability exists in the Free Gifts for WooCommerce plugin, which is used by online stores to manage promotional gift offers. An attacker can inject malicious scripts into the website that execute when a legitimate user or administrator visits certain pages. This could lead to unauthorized actions, theft of sensitive session information, or redirection of customers to fraudulent websites.

Technical details

The Free Gifts for WooCommerce plugin for WordPress suffers from a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation. The flaw allows an unauthenticated attacker to inject malicious scripts into the database, which are later executed in the browser of a victim (typically an administrator or site visitor) when they access the affected page. This vulnerability is assigned a CVSS score of 7.1, reflecting its potential for cross-site impact. The issue is resolved in version 13.3.0.

Affected products

  • Flintop Free Gifts for WooCommerce <= 13.1.0

Timeline

  • 2026-04-20: other: Reported by Nguyen Ba Khanh
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD

References