Impact
The plugin lacks an authorization to request detailed gift‑card data tied to an order ID. The likely attack vector is by sending a request to the vulnerable endpoint with an arbitrary order ID. An attacker can unknowingly trigger the endpoint for metadata, and, for older releases, the active gift‑card redemption code that enables immediate spending. This disclosure crosses confidentiality boundaries and exposes sensitive data that could be used for fraud or identity theft.
Affected Systems
The vulnerability is limited to the Ultimate Gift Cards for WooCommerce plugin versions 3.0.3 through 3.2.9, with 3.2.9 also leaking live redemption codes. Versions 3.2.10 and later include the missing authorization check and are therefore not affected.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of < 1% suggests a low current exploitation probability. The exploitability is relatively low: an attacker needs only to supply an order identifier to the vulnerable endpoint; no authentication is required. The disclosure’s severity is high because it exposes personal data and potentially usable gift‑card codes. The vulnerability is not listed in CISA’s KEV catalog, but its impact on privacy and financial assets warrants immediate review.
OpenCVE Enrichment