Executive brief
The Gift Vouchers plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This could lead to unauthorized actions being performed in a user's browser, such as redirecting visitors to malicious sites or stealing session information. The issue affects all versions up to 4.7.0 and can be resolved by updating to version 4.7.1.
Technical details
The Codemenschen Gift Vouchers plugin for WordPress (versions <= 4.7.0) contains a Stored Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation. An unauthenticated remote attacker can exploit this by injecting malicious scripts into the application, which are then stored and executed in the context of a victim's browser (typically a privileged user) when they visit the affected page. The vulnerability has a CVSS score of 7.1, reflecting its potential for cross-site impact. A fix is available in version 4.7.1.
Affected products
- Codemenschen Gift Vouchers <= 4.7.0
Timeline
- 2026-05-18: other: Reported by researcher xwii
- 2026-07-08: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD
- 2026-07-13: patched: Version 4.7.1 released to address the vulnerability