Executive brief
The Codemenschen Gift Vouchers plugin for WordPress, which allows site owners to manage and sell digital gift cards, contains a security flaw in its access control settings. An unauthorized user could exploit this to perform actions they should not be allowed to do, potentially interfering with voucher management or site operations. This could lead to unauthorized changes to the gift voucher system or minor service disruptions.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the Codemenschen Gift Vouchers plugin (gift-voucher) through version 4.6.9. The flaw is rooted in incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this lack of authorization to perform actions that should be restricted to higher-privileged users. The vulnerability was addressed in version 4.7.0.
Affected products
- Codemenschen Gift Vouchers <= 4.6.9
Timeline
- 2026-05-12: disclosed: Reported by dodoh4t
- 2026-07-08: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD
- 2026-07-13: patched: Version 4.7.0 listed as patched version