← back
CVE-2023-28662criticalCWE-89

CVE-2023-28662

55Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.8epss 42%
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H