CVE-2021-4391: Ultimate Gift Cards for WooCommerce <= 2.1.1 - Cross-Site Request Forgery Bypass
The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwbwgmsavepost() function. This makes it possible for unauthenticated attackers to modify product gift card details via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4391?
CVE-2021-4391 is classified as a moderate severity vulnerability due to its potential exploitation via Cross-Site Request Forgery.
How do I fix CVE-2021-4391?
To fix CVE-2021-4391, update the Ultimate Gift Cards for WooCommerce plugin to version 2.1.2 or higher.
Who is affected by CVE-2021-4391?
CVE-2021-4391 affects users of the Ultimate Gift Cards for WooCommerce plugin for WordPress in versions up to and including 2.1.1.
What type of vulnerability is CVE-2021-4391?
CVE-2021-4391 is a Cross-Site Request Forgery vulnerability caused by missing or incorrect nonce validation.
Can an attacker exploit CVE-2021-4391 without authentication?
Yes, CVE-2021-4391 allows unauthenticated attackers to modify plugin settings and data.