CVE-2026-19436
WPExperts · Ultimate Gift Cards for WooCommerce
The Ultimate Gift Cards for WooCommerce plugin fails to validate gift card values against checkout payments, allowing unauthenticated users to gain excess store credit.
Executive summary
An unauthenticated access control vulnerability in the Ultimate Gift Cards for WooCommerce plugin allows attackers to manipulate store credit values, posing a direct threat to financial integrity.
Vulnerability
This is an improper access control vulnerability (CWE-284) where the plugin fails to reconcile issued gift card coupons against actual checkout payments. The flaw allows unauthenticated remote attackers to trigger the creation of store credit that exceeds the amount paid for the card.
Business impact
The ability for unauthenticated users to generate unauthorized store credit poses a significant risk of direct financial loss and inventory depletion. Given the CVSS score of 7.5, this high severity vulnerability could result in substantial revenue leakage and fraudulent activity if left unpatched.
Remediation
Immediate Action: Update the Ultimate Gift Cards for WooCommerce plugin to version 3.2.10 or later immediately.
Proactive Monitoring: Review WooCommerce order logs and gift card issuance reports for anomalous transactions where the credit value significantly deviates from the payment amount.
Compensating Controls: Implement Web Application Firewall (WAF) rules to monitor and block suspicious checkout requests or excessive coupon generation attempts until the update is deployed.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
This vulnerability represents a critical failure in financial transaction logic that can be exploited by any user without authentication. Administrators must prioritize updating the affected plugin to version 3.2.10 to close this vector and prevent ongoing financial abuse.
More WPExperts CVEs
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Guillermo Álvarez Fernández, with WPScan (coordinator), per the CVE Program record.