First published: Sat Sep 14 2024(Updated: )
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lilmonkee Woocommerce Multiple Free Gift Wordpress | <=1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.