Impact
The GIFT4U plugin for WordPress contains an unauthenticated broken access control flaw in all versions up to 1.0.10. An attacker can exploit this weakness to bypass authentication checks and access restricted plugin functionality, potentially creating or redeeming gift cards without authorization. The vulnerability is classified as CWE-862 – Broken Access Control.
Affected Systems
The affected product is the VillaTheme GIFT4U WordPress plugin. Versions 1.0.10 and earlier are vulnerable. The vulnerability is present regardless of the WordPress core version, as long as the plugin is installed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable functionality without credentials, making exploitation straightforward where the plugin is enabled on a live site. The lack of additional mitigations in the environment makes the risk higher than if the plugin were disabled or restricted to authenticated users.
OpenCVE Enrichment