CVE-2026-19436
moderateUnauthenticated store-credit over-issuance in Ultimate Gift Cards for WooCommerce
CVE-2026-19436 is a business-logic flaw (CWE-284) in the Ultimate Gift Cards for WooCommerce WordPress plugin, which issues gift card coupons to shoppers during checkout. The plugin fails to reconcile the value of the coupon it creates against the amount actually collected at checkout, so an unauthenticated shopper can complete a gift card purchase and receive store credit worth more than the payment they made, with no special conditions, privileges, or user interaction required. An attacker gains excess store credit or coupons on the affected store, which is a direct financial loss (revenue leakage) for the merchant rather than a code-execution or data-exposure issue, consistent with the integrity-only CVSS impact. Any WooCommerce store running the plugin before version 3.2.10 is affected. There is no public proof of concept, the flaw is not in CISA's KEV, and no exploitation is currently known.
What to do: Update the plugin to version 3.2.10 or later, then review recently issued gift card coupons for value-versus-payment mismatches and signs of abuse. Until patched, disabling the gift card purchase/checkout flow is a practical stopgap. Even with no known public PoC, monitor order logs for unauthenticated gift card orders where the issued coupon value is disproportionate to the amount collected.
| Ultimate Gift Cards for WooCommerce (WordPress plugin; plugin author not specifi Ultimate Gift Cards for WooCommerce | All versions before 3.2.10; fixed in 3.2.10 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.