Vulnerabilities and security researches forgift-up gift-up
Direction: descendingMar 29, 2026
Gift Up Gift Cards for WordPress and WooCommerce # CVE-2026-32412
- CVE, Research URL
- Application
- Date
- Mar 14, 2026
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forgery.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through <= 3.1.7.
- Affected versions
-
max 3.1.7.
- Status
-
vulnerable
Jun 06, 2024
Gift Up Gift Cards for WordPress and WooCommerce # CVE-2023-5703
- CVE, Research URL
- Application
- Date
- Nov 07, 2023
- Research Description
- The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'giftup' shortcode in all versions up to, and including, 2.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.22.
- Status
-
vulnerable
Gift Up Gift Cards for WordPress and WooCommerce # CVE-2023-49744
- CVE, Research URL
- Application
- Date
- Dec 15, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through 2.21.3.
- Affected versions
-
max 2.22.
- Status
-
vulnerable