Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42831 | The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lilmonkee:woocommerce_multiple_free_gift:*:*:*:*:*:wordpress:*:* |
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lilmonkee
Lilmonkee woocommerce Multiple Free Gift |
|
| CPEs | cpe:2.3:a:lilmonkee:woocommerce_multiple_free_gift:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lilmonkee
Lilmonkee woocommerce Multiple Free Gift |
|
| Metrics |
ssvc
|
Sat, 14 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift. | |
| Title | WooCommerce Multiple Free Gift <= 1.2.3 - Insufficient Server-Side Validation to Arbitrary Gift Adding | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:24:12.822Z
Reserved: 2022-10-11T20:14:48.297Z
Link: CVE-2022-3459
Updated: 2024-09-16T18:27:55.584Z
Status : Analyzed
Published: 2024-09-14T03:15:02.347
Modified: 2024-09-27T16:43:48.243
Link: CVE-2022-3459
No data.
OpenCVE Enrichment
No data.
EUVD