Impact
The Ultimate Gift Cards for WooCommerce plugin before version 3.2.10 does not confirm that the user redeeming a card is its rightful owner, allowing any authenticated subscriber to redeem gift cards belonging to others. An attacker can therefore zero a victim’s balance and credit the card’s value to themselves, resulting in an outright theft of value.
Affected Systems
All installations of the Ultimate Gift Cards for WooCommerce WordPress plugin with a version earlier than 3.2.10 are affected. The 3.2.9 release added an ownership check on one of the two redemption paths, but the remaining path is still vulnerable if a companion Ultimate Gift Cards for WooCommerce plugin of the same vendor and below 3.2.10 is active. Thus any site running the default plugin version prior to 3.2.10, or the companion plugin prior to 3.2.10, remains at risk.
Risk and Exploitability
The flaw can be abused by any logged‑in user who has permission to redeem gift cards, which typically includes subscribers. Exploitation requires application‑level access: the attacker logs in and uses the normal redemption interface. The CVSS score of 6.5 indicates a moderate‑to‑high‑severity issue. The EPSS score is less than 1%, reflecting a very low but non‑zero chance of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, indicating that the precise exploitation probability is unknown. Because the impact involves monetary loss, the risk to impacted merchants can be significant when gift‑card balances are substantial.
OpenCVE Enrichment