CVE-2026-91020 PUBLISHED

WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount

Assigner: WPScan
Reserved: 14.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product WebToffee Gift Cards for WooCommerce
Versions Default: unaffected
  • affected from 0 to 1.3.1 (excl.)

Credits

  • berke bodur finder
  • WPScan coordinator

References

Problem Types

  • CWE-472 External Control of Assumed-Immutable Web Parameter CWE