VillaTheme 的 GIFT4U(插件名称:gift4u-gift-cards-all-in-one-for-woo)存在权限缺失漏洞,可导致错误配置的访问控制安全级别被利用。该问题影响 GIFT4U 插件的所有版本,从初始版本至 1.1.3。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| VillaTheme | GIFT4U | ≤ 1.1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VillaTheme | GIFT4U | 0 ~ 1.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104398 | 9.8 CRITICAL | WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.10 - PHP Object Injecti |
| CVE-2026-103071 | 7.5 HIGH | WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.3 - Content Injection vu |
| CVE-2026-100161 | 7.2 HIGH | Photo Reviews for WooCommerce <= 1.2.30 - Unauthenticated Stored DOM-Based Cross-Site Scri |
| CVE-2026-103685 | 4.3 MEDIUM | WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2. |
No comments yet