{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-26T14:47:01.346","vulnerabilities":[{"cve":{"id":"CVE-2022-3459","sourceIdentifier":"security@wordfence.com","published":"2024-09-14T03:15:02.347","lastModified":"2026-06-17T04:59:34.180","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift."},{"lang":"es","value":"El complemento WooCommerce Multiple Free Gift para WordPress es vulnerable a la manipulación de obsequios en todas las versiones hasta la 1.2.3 incluida. Esto se debe a que el complemento no aplica controles del lado del servidor en los productos que se pueden agregar como obsequio. Esto hace posible que atacantes no autenticados agreguen artículos que no sean obsequios a su carrito como obsequio."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"ankitpokhrel","product":"WooCommerce Multiple Free Gift","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.2.3","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"lilmonkee","product":"woocommerce_multiple_free_gift","defaultStatus":"unknown","cpes":["cpe:2.3:a:lilmonkee:woocommerce_multiple_free_gift:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThanOrEqual":"1.2.3","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-16T18:26:00.491402Z","id":"CVE-2022-3459","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lilmonkee:woocommerce_multiple_free_gift:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"1.2.3","matchCriteriaId":"09B59D2F-8433-47E5-9FDC-7B65D2FD5D3F"}]}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-multiple-free-gift/trunk/lib/WFG_Frontend.class.php#L189","source":"security@wordfence.com","tags":["Product"]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cdb9c321-1a2c-4593-9947-2071a908ee1c?source=cve","source":"security@wordfence.com","tags":["Third Party Advisory"]}]}}]}