S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-16159 Scanner

CVE-2018-16159 scanner - SQL Injection (SQLi) vulnerability in Gift Vouchers plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16159
9.8
CVSS

The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Gift Vouchers plugin for WordPress is a popular tool used by online retailers and small businesses to create and sell digital gift vouchers. These vouchers can be customized, offer discounts, and include unique promotional codes for customers to use. This plugin helps businesses expand their customer base, increase sales, and enhance their marketing strategies.

However, the Gift Vouchers plugin has recently been detected with a critical security vulnerability: CVE-2018-16159. This vulnerability allows an attacker to inject malicious SQL code into the template_id parameter of the wp-admin/admin-ajax.php wpgv_doajax_front_template request. This allows the attacker to access sensitive information on the database, make changes or deletions to data, or even gain unauthorized access to the website itself.

If this vulnerability is exploited, it could lead to disastrous consequences for the website owner. Sensitive customer information such as names, email addresses, and financial data could be stolen. The attacker could also gain unauthorized access to the website's backend, gaining administrative privileges and controlling the entire website.

Using the s4e.io platform, businesses and website owners can access powerful tools and resources that enable them to quickly and easily identify, assess, and mitigate vulnerabilities in their digital assets. With pro features such as vulnerability scanning, risk assessment, and expert advice, s4e.io provides comprehensive protection against security threats and can prevent serious data breaches. By utilizing these tools and taking the necessary precautions, businesses can keep their customers' information safe and secure, without compromising their growth and success.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners who use the Gift Vouchers plugin should take immediate precautions. Some measures that can be taken include:

  • Update the Gift Vouchers plugin to its latest version, which includes patches for this vulnerability.
  • Limit access to the wp-admin/admin-ajax.php file for untrusted users.
  • Increase security measures for authentication and authorization, such as changing passwords or implementing two-factor authentication.
  • Regularly monitor the website and database for suspicious activity, and take timely action if a threat is detected.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-16159 scanner - SQL Injection (SQLi) vulnerability in Gift Vouchers plugin for WordPress | S4E