Record summary

CVE-2023-28662 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Gift Cards (Gift Vouchers and Packages) WordPress Plugin

CVE List<= 4.3.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordpress Gift Cards <= 4.3.1 - SQL InjectionCVSS 9.8

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

Impact

Successful exploitation of this vulnerability could allow an attacker to perform SQL injection attacks, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.

Remediation

Update the Gift Cards (Gift Vouchers and Packages) WordPress Plugin to the latest version available.

WeaknessesCWE-89
Authorsxxcdd
Template tagstime-based-sqlicvecve2023wordpresswpwp-pluginsqliunauthgift-vouchercodemenschenvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:codemenschen:gift_vouchers:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/gift-voucher/"
FOFA: body="/wp-content/plugins/gift-voucher/"

Source: ProjectDiscovery

References

2