Vulnerability. Gift card codes accesible
-
Hi, I’ve using the plugin for over a year, and it has been working correctly. On october we created around 20 gift cards manually to reward some clients. One of them used his last night correctly, and somehow used 16 others buying the same product with the same discount (using different gift card codes not sent to him) until the product run out of stock. Only the first purchase showed the discount code at the orders page on woocommerce, but they all showed it on our new order email notifications. Then he proceeded to use the purchase points he won with his purchases, by buying other products.
We proceeded to deactivate the plugin and cancel all his orders and points, and are waiting for him to send us his bank info to send him his money back.
If I can help with something, let me know.The page I need help with: [log in to see the link]
- You must be logged in to reply to this topic.