Back

MEDIUM

WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount

Published Oct 2, 2026

Description

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Oct 2, 2026
Updated Oct 2, 2026
Reserved Sep 14, 2026
CISA Vulnrichment
Updated Oct 2, 2026
NVD
Status Deferred
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Oct 2, 2026
Updated Oct 2, 2026
Exploited since n/a
EUVD-2026-91214