Impact
The WebToffee Gift Cards for WooCommerce plugin before version 1.3.1 fails to validate a user‑supplied amount before using it as the cart‑item price and store‑credit coupon value. An attacker can submit an arbitrary or negative amount by supplying the "wt_credit_amount" parameter, bypassing the predefined denominations and reducing or eliminating the order total. This flaw can allow the acquisition of products without payment, essentially creating a vendor‑side fraud exploit.
Affected Systems
WordPress sites running the WebToffee Gift Cards for WooCommerce plugin at any version prior to 1.3.1 are affected. The vulnerability is tied to the plugin’s server‑side processing of the gift‑card amount input.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw over the web by sending unauthenticated requests, so the primary vector is remote. Because no authentication is required to submit the amount, any visitor to the site can potentially manipulate the order total.
OpenCVE Enrichment