CVE-2024-11423: Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch
The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances without purchasing anything.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11423?
CVE-2024-11423 has been classified with a high severity due to its potential for unauthorized modifications.
How do I fix CVE-2024-11423?
To mitigate the risk of CVE-2024-11423, update the Ultimate Gift Cards for WooCommerce plugin to version 3.0.7 or later.
Who is affected by CVE-2024-11423?
Users of the Ultimate Gift Cards for WooCommerce plugin, specifically those using versions up to 3.0.6, are affected by CVE-2024-11423.
What versions of the Ultimate Gift Cards for WooCommerce are vulnerable to CVE-2024-11423?
CVE-2024-11423 affects all versions of the Ultimate Gift Cards for WooCommerce plugin up to and including version 3.0.6.
What type of vulnerability is CVE-2024-11423?
CVE-2024-11423 is classified as a security vulnerability that allows for unauthorized modification of gift card data.