Sceawere

Vulnerability Detail

CVE-2026-91020UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WebToffee Gift Cards Price Manipulation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
16h ago
Vendor
Unknown
Product
WebToffee Gift Cards for WooCommerce
Attack Type
CWE-472 External Control of Assumed-Immutable Web Parameter
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T07:16:38.493Z",
  "pubdate": "2026-10-02T07:16:38.493Z",
  "executiveSummary": "The WebToffee Gift Cards for WooCommerce plugin prior to version 1.3.1 contains a critical input validation vulnerability.\nThe vulnerability is categorized as an improper input validation flaw, specifically concerning the manipulation of monetary values during the cart-addition process.\nThe flaw allows unauthenticated attackers to supply arbitrary or negative amounts for gift card purchases, bypassing server-side denomination constraints.\nBy manipulating the gift card price and corresponding store-credit coupon value, an attacker can influence the total order value, potentially allowing the acquisition of store products without valid payment.\nThe impact includes financial loss for the merchant and the potential for unauthorized privilege escalation within the store's credit system.\nThis vulnerability requires no special privileges or authentication, making it reachable via standard web requests to the e-commerce storefront.\nThe risk is classified as critical, as it directly facilitates fraud by circumventing established business logic governing price and credit generation.",
  "technicalDetails": "The root cause of the vulnerability lies in the plugin's failure to perform server-side validation on the 'gift card amount' parameter before processing it as a cart item price.\nSpecifically, the application logic trustingly accepts the client-supplied input for the gift card denomination. Because there is no server-side verification against the configured settings or price lists, the input is treated as a trusted value in the WooCommerce cart calculation engine.\nThe exploitation flow begins when an unauthenticated attacker identifies the gift card product URL. By intercepting the POST request used to add the item to the cart, the attacker can modify the input parameter representing the gift card amount.\nBy submitting an arbitrary numeric value, or a negative value, the attacker forces the application to set the price of the cart item to that user-defined amount.\nWhen the gift card is processed as store credit, the system uses this unvalidated value to determine the coupon's worth. If a negative value is submitted, the cart total calculation may incorrectly decrement the final order amount, potentially resulting in a free order or generating surplus store credit at the expense of the merchant.\nBecause the vulnerability occurs during the request-to-cart transition, it does not require authentication or elevated administrative privileges. The attack is performed via standard HTTP interaction with the vulnerable WooCommerce endpoint.\nThe affected component is the logic responsible for handling 'user-supplied price' gift cards. This component fails to verify that the value provided matches expected constraints defined in the WooCommerce settings.\nPost-exploitation, the attacker can successfully checkout products while leveraging the manipulated store-credit coupon, which effectively results in a payment bypass. The system fails to reconcile the actual payment collected against the value assigned to the credit token, enabling the unauthorized acquisition of goods.\nThis flaw demonstrates an failure of secure design in e-commerce workflows, where client-side input is permitted to dictate server-side financial calculations without secondary reconciliation or validation."
}
CVE-2026-91020: WebToffee Gift Cards Price Manipulation (MEDIUM Severity, CVSS: 5.3) | Sceawere