CVE-2024-13520 MEDIUM

CVE-2024-13520: Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.9 - Missing Authorization to Unauthenticated Price, Date, and Note Updates

Vendor Codemenschen
Product Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Weakness CWE-862 · Missing authorization
Published February 20, 2025
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.9. This makes it possible for unauthenticated attackers to update the value, expiration date, and user note for any gift voucher.

Explanation of Vulnerability in Simple Terms

02Summary

The Gift Cards plugin for WooCommerce contains an authorization flaw that allows unauthenticated attackers to modify gift card data. An attacker can send network requests without authentication to alter gift card records, potentially affecting the integrity of gift card transactions. The vulnerability requires no user interaction and affects all versions up to 4.4.9.

What an attacker can do

03Attacker Capabilities

Modify gift card data without authentication or permission.

Potential impact on your site

04Site Impact

Gift card records can be altered by unauthorized parties, risking fraud and transaction integrity.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

February 20, 2025 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE