CVE-2026-103357: WordPress GIFT4U plugin <= 1.1.3 - Broken Access Control vulnerability
Published Oct 10, 2026
·Updated
Missing Authorization vulnerability in VillaTheme GIFT4U gift4u-gift-cards-all-in-one-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GIFT4U: from n/a through 1.1.3.
Affected Software
1 affected component
Villatheme GIFT4U<=1.1.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GIFT4U pluginto a version that resolves this vulnerability.Fixed in 1.1.4
Event History
Oct 10, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
GIFT4U versions through 1.1.3 are affected. The affected plugin is identified as gift4u-gift-cards-all-in-one-for-woo.
2
Does exploitation require an authenticated WordPress account or user interaction?
The CVSS vector indicates network reachability, no privileges required, and no user interaction required. It also indicates a low integrity impact, with no confidentiality or availability impact listed.