CVE-2026-19439
moderateUnauthenticated Data Exposure in Ultimate Gift Cards for WooCommerce
The Ultimate Gift Cards for WooCommerce WordPress plugin before version 3.2.10 lacks an authorization check when displaying gift card details, allowing any unauthenticated visitor to retrieve the gift cards attached to arbitrary orders. An attacker who can trigger this display for orders on a vulnerable store obtains customer personal data, gift card balances and dates; on version 3.2.9 the live redemption code is also exposed, which anyone holding it can redeem. Versions 3.0.3 through 3.2.8 disclose the same data but without the redemption code. Any WooCommerce store running the plugin in the affected range is exposed, with risk concentrated on stores that actively sell gift cards. There is no known public proof-of-concept and the flaw is not in CISA's KEV, so confirmed in-the-wild exploitation has not been reported.
What to do: Upgrade Ultimate Gift Cards for WooCommerce to version 3.2.10 or later. Stores that ran version 3.2.9 should review gift card orders for unauthorized redemptions and consider reissuing any redemption codes that may have been exposed. As an interim mitigation, restrict unauthenticated requests to the plugin's gift card display functionality (e.g., via WAF rules) until the update is applied.
| WP Swings Ultimate Gift Cards for WooCommerce (WordPress plugin) | 3.0.3 through 3.2.9 (all versions before 3.2.10; 3.2.9 additionally exposes the live redemption code, 3.0.3-3.2.8 expose data without the code) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend. Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.