CVE-2023-28662

CRITICAL NUCLEI

The Gift Cards <4.3.1 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-28662 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

Nuclei Templates (1)

Wordpress Gift Cards <= 4.3.1 - SQL Injection
CRITICALby xxcdd
Shodan: http.html:"/wp-content/plugins/gift-voucher/"
FOFA: body="/wp-content/plugins/gift-voucher/"

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.4219
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
codemenschen/gift_vouchers < 4.3.1
Published Mar 22, 2023
Tracked Since Feb 18, 2026