ZeroHour

CVE-2026-19439

moderate

Unauthenticated Data Exposure in Ultimate Gift Cards for WooCommerce

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

The Ultimate Gift Cards for WooCommerce WordPress plugin before version 3.2.10 lacks an authorization check when displaying gift card details, allowing any unauthenticated visitor to retrieve the gift cards attached to arbitrary orders. An attacker who can trigger this display for orders on a vulnerable store obtains customer personal data, gift card balances and dates; on version 3.2.9 the live redemption code is also exposed, which anyone holding it can redeem. Versions 3.0.3 through 3.2.8 disclose the same data but without the redemption code. Any WooCommerce store running the plugin in the affected range is exposed, with risk concentrated on stores that actively sell gift cards. There is no known public proof-of-concept and the flaw is not in CISA's KEV, so confirmed in-the-wild exploitation has not been reported.

What to do: Upgrade Ultimate Gift Cards for WooCommerce to version 3.2.10 or later. Stores that ran version 3.2.9 should review gift card orders for unauthorized redemptions and consider reissuing any redemption codes that may have been exposed. As an interim mitigation, restrict unauthenticated requests to the plugin's gift card display functionality (e.g., via WAF rules) until the update is applied.

Affected
WP Swings Ultimate Gift Cards for WooCommerce (WordPress plugin)3.0.3 through 3.2.9 (all versions before 3.2.10; 3.2.9 additionally exposes the live redemption code, 3.0.3-3.2.8 expose data without the code)
Estimated exposure
moderateroughly 20,000 WooCommerce sites (plugin's WordPress.org active-install count is in the tens of thousands) — Based on the plugin's public WordPress.org active-install count in the tens of thousands; the number of actually exposed data records is likely higher, since each vulnerable store's gift card orders and customer records can be queried…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend. Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.

Ecosystems
WordPress, E-commerce
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.