VYPR
Medium severity4.3NVD Advisory· Published Apr 1, 2025· Updated Apr 23, 2026

CVE-2025-31781

CVE-2025-31781

Description

Missing authorization vulnerability in Gift Cards for WooCommerce up to version 1.5.8 allows attackers to exploit incorrectly configured access control security levels.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization vulnerability in Gift Cards for WooCommerce up to version 1.5.8 allows attackers to exploit incorrectly configured access control security levels.

Vulnerability

The Gift Cards for WooCommerce plugin (woo-giftcards) versions 1.5.8 and below contain a missing authorization vulnerability [1]. The issue resides in the plugin's access control mechanisms, which are incorrectly configured, allowing exploitation without proper permission checks. The plugin requires WooCommerce to be installed and activated, with WooCommerce Coupons enabled in settings [1]. Affected versions include all releases from n/a through 1.5.8.

Exploitation

An attacker needs no special privileges or authentication, as the vulnerability lies in incorrectly configured access control security levels [1]. By crafting a request that bypasses permission checks, an attacker can exploit the missing authorization to perform actions that should require higher-level access. No user interaction is required beyond the attacker sending the exploit request.

Impact

Successful exploitation allows an attacker to access unauthorized functionality within the plugin, potentially leading to information disclosure or modification of gift card data [1]. The exact privilege level gained depends on the missing authorization, but it could enable an attacker to create, modify, or view gift cards without proper permissions, impacting the confidentiality and integrity of WooCommerce gift card operations.

Mitigation

As of the publication date, no fixed version has been released [1]. Users should update to a patched version once available and review their site's access control configurations. The plugin has not been updated since 2023-08-14 and has limited support [1]. There is no known workaround described in available references.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.