Input validation vulnerability in Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) 4.4.4

The Gift Cards plugin for WordPress, which allows for the purchase and use of gift vouchers and packages, has a security vulnerability. This vulnerability, known as Stored Cross-Site Scripting, can be exploited through the uploading of SVG files. This means that attackers who have Author-level access or higher can inject harmful code into pages, which will then run when a user views the SVG file.

Detected in:

Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) open vulnerable versions: >= * <= 4.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.