S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-28662 Scanner

CVE-2023-28662 Scanner - SQL Injection (SQLi) vulnerability in Gift Cards (Gift Vouchers and Packages) WordPress Plugin

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-28662
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Gift Cards (Gift Vouchers and Packages) WordPress Pluginby n/a
<= 4.3.1
Updated Aug 22, 2026View on NVD →
Detail

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin is widely used by businesses and individuals aiming to offer digital gift vouchers through their WordPress websites. This plugin facilitates easy management and customization of gift card offerings, allowing for differentiated packages and vouchers. It is frequently utilized in e-commerce settings for promotional purposes and customer retention. The plugin is maintained by developers using the WordPress framework, and it integrates seamlessly into websites to support online commercial strategies. With its comprehensive features, the plugin provides a practical tool for expanding online business functionalities. Its user-friendly interface and compatibility make it a popular choice among WordPress users.

The vulnerability detected in the Gift Cards WordPress Plugin is a critical SQL Injection issue. SQL Injection vulnerabilities allow attackers to manipulate the database queries executed by the application. This specific vulnerability exists in the 'template' parameter within the 'wpgv_doajax_voucher_pdf_save_func' action, which fails to validate user input properly. Through this, malicious users can craft requests to execute arbitrary SQL commands on the database. This can lead to unauthorized data access or modification. The issue is particularly alarming because it can be exploited without authentication.

Technically, the vulnerability stems from insufficient input validation on the 'template' parameter. The plugin does not sanitize or prepare the input properly before using it in SQL queries. The affected parameter is handled directly by database operations, which an attacker can exploit to perform time-based SQL injections. The exploit involves sending crafted POST requests to the server with specific input that manipulates the database response time to infer information. The attack can be confirmed by measuring response delays and error messages returned from the plugin.

If exploited, this SQL Injection vulnerability could have severe consequences. Attackers might gain unauthorized access to sensitive data, such as user credentials and payment information. They could alter or delete crucial database information, severely disrupting the website's operations. In worst-case scenarios, it might lead to full-site compromise, allowing attackers to install backdoors or malware. This could further harm the website's reputation and user trust, leading to a potential loss of business.

REFERENCES

Solution Advice
  • Update the Gift Cards (Gift Vouchers and Packages) WordPress Plugin to the latest version available.
  • Implement strict input validation on all user inputs, particularly those affecting database queries.
  • Consider using prepared statements and parameterized queries to prevent SQL Injection vulnerabilities.
  • Regularly audit and test web applications for vulnerabilities as part of a comprehensive security strategy.
  • Educate developers on secure coding practices to avoid similar vulnerabilities in future developments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.