Impact
The vulnerability is a missing authorization flaw that permits users to access protected gift card functions without proper privileges. Exploiting this weakness can let an attacker manage or view gift card data beyond their assigned permissions. The weakness is categorized as CWE-862, indicating inadequate enforcement of access control rules.
Affected Systems
The affected product is the WordPress plugin Gift Cards for WooCommerce, versions from the earliest released build through 1.5.8. Any WordPress site using this plugin within this version range is at risk.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the medium severity range. The EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation, and the flaw is not yet listed in CISA's KEV catalog. Attackers would need to identify and target a site running the vulnerable plugin, and then use the exposed access control bypass to elevate privileges or perform unauthorized actions.
OpenCVE Enrichment
EUVD