CVE-2026-19439
Ultimate · Gift Cards for WooCommerce
The Ultimate Gift Cards for WooCommerce plugin lacks authorization checks, allowing unauthenticated attackers to retrieve gift card details, customer data, and live redemption codes from arbitrary orders.
Executive summary
A critical authorization flaw in the Ultimate Gift Cards for WooCommerce plugin enables unauthenticated attackers to harvest sensitive customer information and redeemable gift card codes.
Vulnerability
This vulnerability is an information exposure issue resulting from a missing authorization check. Unauthenticated users can query the plugin to access gift card data, including customer personal information and live redemption codes, which permits unauthorized spending of funds.
Business impact
The exposure of customer personal data and active gift card redemption codes presents a significant risk of financial loss and privacy violations. Given the CVSS score of 7.5, this high severity vulnerability could lead to direct monetary theft and severe damage to customer trust if exploited to drain active gift card balances.
Remediation
Immediate Action: Update the Ultimate Gift Cards for WooCommerce plugin to version 3.2.10 or later immediately to enforce necessary authorization checks.
Proactive Monitoring: Review application access logs for unusual patterns of requests directed at gift card endpoints, particularly those originating from unauthorized or anonymous user sessions.
Compensating Controls: If immediate patching is not feasible, implement Web Application Firewall rules to block unauthorized access attempts targeting the plugin's gift card retrieval functions.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent financial fraud and unauthorized data access. Administrators must prioritize updating the plugin to version 3.2.10 to close the authorization gap and protect customer assets.
More Ultimate CVEs
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Usama Arshad, with WPScan (coordinator), per the CVE Program record.