Description
The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated manipulation of gift card amount leading to unauthorized purchases
Action: Patch
AI Analysis

Impact

The WebToffee Gift Cards for WooCommerce plugin before version 1.3.1 fails to validate a user‑supplied amount before using it as the cart‑item price and store‑credit coupon value. An attacker can submit an arbitrary or negative amount by supplying the "wt_credit_amount" parameter, bypassing the predefined denominations and reducing or eliminating the order total. This flaw can allow the acquisition of products without payment, essentially creating a vendor‑side fraud exploit.

Affected Systems

WordPress sites running the WebToffee Gift Cards for WooCommerce plugin at any version prior to 1.3.1 are affected. The vulnerability is tied to the plugin’s server‑side processing of the gift‑card amount input.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, while the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw over the web by sending unauthenticated requests, so the primary vector is remote. Because no authentication is required to submit the amount, any visitor to the site can potentially manipulate the order total.

Generated by OpenCVE AI on October 2, 2026 at 13:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WebToffee Gift Cards for WooCommerce plugin to version 1.3.1 or newer to enable server‑side validation of gift card amounts.
  • If an upgrade is not immediately possible, disable the gift‑card functionality in the plugin settings or by removing the associated shortcode/action so that the vulnerable endpoint cannot be reached.
  • Ensure that any custom code or overrides that handle gift‑card amounts perform strict numeric validation—reject values outside the allowed denominations or negative numbers before applying them to cart totals.

Generated by OpenCVE AI on October 2, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-472
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.
Title WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:10.137Z

Reserved: 2026-09-14T16:53:32.098Z

Link: CVE-2026-91020

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:34.099Z

cve-icon NVD

Status : Received

Published: 2026-10-02T07:16:38.493

Modified: 2026-10-02T11:17:36.850

Link: CVE-2026-91020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:00:18Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-472

    External Control of Assumed-Immutable Web Parameter