CVE-2026-19436

WPExperts · Ultimate Gift Cards for WooCommerce

The Ultimate Gift Cards for WooCommerce plugin fails to validate gift card values against checkout payments, allowing unauthenticated users to gain excess store credit.

Executive summary

An unauthenticated access control vulnerability in the Ultimate Gift Cards for WooCommerce plugin allows attackers to manipulate store credit values, posing a direct threat to financial integrity.

Vulnerability

This is an improper access control vulnerability (CWE-284) where the plugin fails to reconcile issued gift card coupons against actual checkout payments. The flaw allows unauthenticated remote attackers to trigger the creation of store credit that exceeds the amount paid for the card.

Business impact

The ability for unauthenticated users to generate unauthorized store credit poses a significant risk of direct financial loss and inventory depletion. Given the CVSS score of 7.5, this high severity vulnerability could result in substantial revenue leakage and fraudulent activity if left unpatched.

Remediation

Immediate Action: Update the Ultimate Gift Cards for WooCommerce plugin to version 3.2.10 or later immediately.

Proactive Monitoring: Review WooCommerce order logs and gift card issuance reports for anomalous transactions where the credit value significantly deviates from the payment amount.

Compensating Controls: Implement Web Application Firewall (WAF) rules to monitor and block suspicious checkout requests or excessive coupon generation attempts until the update is deployed.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

This vulnerability represents a critical failure in financial transaction logic that can be exploited by any user without authentication. Administrators must prioritize updating the affected plugin to version 3.2.10 to close this vector and prevent ongoing financial abuse.

More WPExperts CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Guillermo Álvarez Fernández, with WPScan (coordinator), per the CVE Program record.