CVE-2023-28662

CRITICAL NUCLEI

The Gift Cards <4.3.1 - SQL Injection

Title source: llm

Description

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

Nuclei Templates (1)

Wordpress Gift Cards <= 4.3.1 - SQL Injection
CRITICALby xxcdd
Shodan: http.html:"/wp-content/plugins/gift-voucher/"
FOFA: body="/wp-content/plugins/gift-voucher/"

Scores

CVSS v3 9.8
EPSS 0.7425
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
codemenschen/gift_vouchers < 4.3.1
Published Mar 22, 2023
Tracked Since Feb 18, 2026