๐Ÿ” CVE Alert

CVE-2026-32412

MEDIUM 5.4

WordPress Gift Up Gift Cards for WordPress and WooCommerce plugin <= 3.1.7 - Server Side Request Forgery (SSRF) vulnerability

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
10th

Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forgery.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through <= 3.1.7.

CWE CWE-918
Vendor gift up!
Product gift up gift cards for wordpress and woocommerce
Published Mar 13, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for gift up! gift up gift cards for wordpress and woocommerce

Be the first to know when new medium vulnerabilities affecting gift up! gift up gift cards for wordpress and woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gift Up! / Gift Up Gift Cards for WordPress and WooCommerce
0 โ‰ค 3.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/gift-up/vulnerability/wordpress-gift-up-gift-cards-for-wordpress-and-woocommerce-plugin-3-1-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve

Credits

Nguyen Ba Khanh | Patchstack Bug Bounty Program