{"id":"CVE-2026-91020","title":"The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to…","summary":"The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-472"],"product":"WebToffee Gift Cards for WooCommerce","affected":["webtoffee_gift_cards_for_woocommerce < 1.3.1"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T11:17:36.850","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91020","references":[{"url":"https://wpscan.com/vulnerability/998db4a0-693c-4701-a37e-ec33002e1417/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-02T10:48:13.420045Z"},"ingestedAt":"2026-10-02T07:13:06.668Z","slug":"CVE-2026-91020","body":"## Overview\n\nThe WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}