Medium 4.3
2025-03-27< 1.7.9
CVE-2025-30923
Minimum safe version
1.7.9
Update to 1.7.9 or later to address 6 fixable vulnerabilities
CVE-2025-30923
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Gift Message for WooCommerce Plugin <= 1.7.4 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Gift Message for WooCommerce plugin <= 1.5.0 - Sensitive Information Disclosure vulnerability
WordPress Gift Message for WooCommerce plugin <= 1.5.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability