1 results (0.001 seconds)
CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 2
CVE-2024-11423 – Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch
https://notcve.org/view.php?id=CVE-2024-11423
07 Jan 2025 — The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge... • https://packetstorm.news/files/id/183442 • CWE-862: Missing Authorization •