CVE-2026-91020
Received Received - Intake

Unauthenticated Price Manipulation in WebToffee Gift Cards for WooCommerce

Vulnerability report for CVE-2026-91020, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
webtoffee gift_cards_for_woocommerce to 1.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WebToffee Gift Cards for WooCommerce WordPress plugin before version 1.3.1. It allows unauthenticated users to submit arbitrary or negative gift card amounts via the wt_credit_amount parameter. The plugin fails to validate this input server-side, enabling manipulation of cart-item prices and store-credit coupon values. Attackers can set these values to any amount, including negative values, to alter the order total and obtain products without payment.

Detection Guidance

Check the installed version of the WebToffee Gift Cards for WooCommerce plugin. If it is below 1.3.1, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

If you use the affected plugin version, attackers could exploit this to purchase products without paying by setting negative or arbitrary prices. This could lead to financial losses, unauthorized discounts, or store-credit manipulation. The vulnerability requires no authentication, making it accessible to any user.

Compliance Impact

This vulnerability could lead to financial fraud by allowing unauthorized manipulation of order totals, which may violate compliance requirements for data integrity and financial transaction accuracy in standards like GDPR (data protection) and HIPAA (healthcare transactions). Unauthorized order manipulation may also conflict with audit and record-keeping obligations under these regulations.

Mitigation Strategies

Update the WebToffee Gift Cards for WooCommerce plugin to version 1.3.1 or later immediately. If updating is not possible, consider disabling the plugin temporarily until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91020. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart