Description
Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4.
Published: 2026-02-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the WP Swings Ultimate Gift Cards For WooCommerce plugin. Incorrectly configured access control allows attackers to perform privileged actions, such as creating, modifying, or deleting gift cards, without proper permission. The flaw maps to CWE‑862 and could lead to unauthorized manipulation of store inventory and financial data.

Affected Systems

Vendors impacted are WP Swings’ Ultimate Gift Cards For WooCommerce, commonly known as woo‑gift‑cards‑lite. All installations of the plugin up to version 3.2.4 are affected. This includes environments that have not applied the latest patch, as the issue exists from the earliest release through 3.2.4.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate level of severity, while the EPSS score of less than 1 % signals that the vulnerability has a low probability of being exploited at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send crafted requests to the plugin’s exposed endpoints; the missing authorization check makes the exploit relatively straightforward for anyone with access to the site’s back‑end. Based on the description, this vulnerability is likely exploitable via the web interface. Given the moderate impact and low exploit reputation, the risk is moderate but still warrants prompt mitigation.

Generated by OpenCVE AI on April 16, 2026 at 00:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Swings Ultimate Gift Cards For WooCommerce plugin to the latest released version that resolves the authorization issue.
  • If the latest version cannot be applied immediately, limit access to the plugin’s administrative endpoints to users with administrator or shop manager roles only, and review existing role permissions.
  • If gift card functionality is not essential at the time, consider disabling or uninstalling the plugin until the issue is fixed.

Generated by OpenCVE AI on April 16, 2026 at 00:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings ultimate Gift Cards For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings ultimate Gift Cards For Woocommerce

Fri, 20 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4.
Title WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
Wpswings Ultimate Gift Cards For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:14:09.586Z

Reserved: 2026-01-22T14:42:40.516Z

Link: CVE-2026-24375

cve-icon Vulnrichment

Updated: 2026-02-19T21:17:20.051Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T09:16:13.497

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-24375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T00:45:15Z

Weaknesses