Description
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
Published: 2026-09-10
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Ultimate Gift Cards for WooCommerce plugin before version 3.2.10. When a customer completes a checkout, the plugin fails to verify that the value of the gift card coupon matches the amount actually collected. This allows an attacker who does not need to be logged in to create a gift card that has a higher value than the money spent, effectively giving them store credit for free. The result is an unauthorized financial gain for the user and an equivalent loss for the store.

Affected Systems

WordPress sites that use the Ultimate Gift Cards for WooCommerce plugin, any version earlier than 3.2.10. No other product or vendor details were supplied.

Risk and Exploitability

The vendor has not published an EPSS score or KEV status, so the exact likelihood of exploitation is unknown. However, because the flaw can be triggered without authentication and simply by completing the normal checkout process, the potential for abuse is high for any site that hosts the affected plugin. Administrators should treat this as a high‑risk issue and apply the fix promptly.

Generated by OpenCVE AI on September 10, 2026 at 07:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ultimate Gift Cards for WooCommerce to version 3.2.10 or later, which corrects the reconciliation logic.
  • If an update cannot be performed immediately, disable or block the issuance of gift card coupons for unauthenticated visitors until the plugin is patched to prevent inflated credit.
  • Verify the checkout flow after applying the fix or the interim block to ensure no gift card value exceeds the payment amount.

Generated by OpenCVE AI on September 10, 2026 at 07:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-640

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
Title Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation via Discounted Purchase
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-10T06:00:05.523Z

Reserved: 2026-08-10T12:44:06.866Z

Link: CVE-2026-19436

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T07:17:02.620

Modified: 2026-09-10T07:17:02.620

Link: CVE-2026-19436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:30:07Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password