Gift Cards for WooCommerce
Gift Cards for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Gift Cards for WooCommerce has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Kévin Mosbahi (Mika). Gift Cards for WooCommerce is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2025-31781Gift Cards for WooCommerce <= 1.5.8 - Missing Authorization
Read the full analysisVulnerability Records
Gift Cards for WooCommerce
Author
ahmadshyk
Requirements The plugin requires WooCommerce to be installed and activated. WooCommerce Coupons should be enabled from WooCommerce Settings. How it Works Add new product as gift card (See Screenshot Below) Default Add to Cart button will be remove from gift card product, it will add new button “Buy Gift Card” The plugin will add form on gift card page where your customers can add recipient information. After successful gift card purchase and when order status turns to processing, it will generate new coupon of format xxxx-xxxx-xxxx-xxxx and send to recipient. Once email is sent, recipient can click the button in the email, it will redirect recipient to the site and apply coupon immediately. More options in Pro Version Add Giftcards as variable products. An option to add coupon prefix. Send Giftcard to multiple recipients. Options to edit frontend labels and messages. Fully Customize the Giftcard email content. Multiple time giftcard usage (If Giftcard worth more than the previous order) Shortcode to check remaining amount left on Giftcard. Documentation For step by step setup, Click here Support If you are facing any issue or want to report a bug, feel free to reach me at a.hassan@ahmadshyk.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C