Impact
The vulnerability is a missing authorization flaw in the WP Swings Ultimate Gift Cards For WooCommerce plugin. Incorrectly configured access control allows attackers to perform privileged actions, such as creating, modifying, or deleting gift cards, without proper permission. The flaw maps to CWE‑862 and could lead to unauthorized manipulation of store inventory and financial data.
Affected Systems
Vendors impacted are WP Swings’ Ultimate Gift Cards For WooCommerce, commonly known as woo‑gift‑cards‑lite. All installations of the plugin up to version 3.2.4 are affected. This includes environments that have not applied the latest patch, as the issue exists from the earliest release through 3.2.4.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of severity, while the EPSS score of less than 1 % signals that the vulnerability has a low probability of being exploited at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send crafted requests to the plugin’s exposed endpoints; the missing authorization check makes the exploit relatively straightforward for anyone with access to the site’s back‑end. Based on the description, this vulnerability is likely exploitable via the web interface. Given the moderate impact and low exploit reputation, the risk is moderate but still warrants prompt mitigation.
OpenCVE Enrichment