Impact
The vulnerability is in the Ultimate Gift Cards for WooCommerce plugin before version 3.2.10. When a customer completes a checkout, the plugin fails to verify that the value of the gift card coupon matches the amount actually collected. This allows an attacker who does not need to be logged in to create a gift card that has a higher value than the money spent, effectively giving them store credit for free. The result is an unauthorized financial gain for the user and an equivalent loss for the store.
Affected Systems
WordPress sites that use the Ultimate Gift Cards for WooCommerce plugin, any version earlier than 3.2.10. No other product or vendor details were supplied.
Risk and Exploitability
The vendor has not published an EPSS score or KEV status, so the exact likelihood of exploitation is unknown. However, because the flaw can be triggered without authentication and simply by completing the normal checkout process, the potential for abuse is high for any site that hosts the affected plugin. Administrators should treat this as a high‑risk issue and apply the fix promptly.
OpenCVE Enrichment