Description
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control that allows attackers to manipulate gift card records in the WordPress Ultimate Gift Cards For WooCommerce plugin without authenticating as a privileged user. This could let attackers create, edit, or delete gift cards, altering their values or generating fraudulent discounts or unauthorized payouts. The weakness corresponds to CWE‑862, which defines authorization check failures.

Affected Systems

All WordPress sites that have installed the WP Swings Ultimate Gift Cards For WooCommerce plugin at version 3.2.9 or earlier are affected. The issue is confined to the plugin component and does not extend to other WordPress core or plugin code. Site administrators should check the plugin version and upgrade if necessary.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is through the plugin’s administrative endpoints accessed via the web interface. The CVSS score of 5.3 indicates moderate risk, and the absence of a KEV listing does not imply low threat. EPSS information is not available, but the nature of the flaw suggests the exploitation probability may be significant in environments where the plugin’s admin URLs are reachable from the internet. An attacker would need to discover the plugin’s management endpoints, then issue requests to create, edit or delete gift cards, potentially generating fraudulent discounts or unauthorized payouts.

Generated by OpenCVE AI on September 2, 2026 at 12:51 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Gift Cards For WooCommerce Plugin to the latest available version (at least 3.2.10).


OpenCVE Recommended Actions

  • Update the WordPress Ultimate Gift Cards For WooCommerce Plugin to version 3.2.10 or later
  • If an immediate update is not possible, restrict access to the plugin’s administrative pages to only trusted roles or IP addresses, effectively blocking unauthenticated requests
  • Implement a web application firewall rule or rate limiting to detect and block suspicious request patterns targeting gift card URLs
  • Regularly review transaction logs for unexpected gift card creation or revocation activity

Generated by OpenCVE AI on September 2, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings ultimate Gift Cards For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings ultimate Gift Cards For Woocommerce

Wed, 02 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Title WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wpswings Ultimate Gift Cards For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-02T12:33:05.545Z

Reserved: 2026-09-02T09:57:31.410Z

Link: CVE-2026-84760

cve-icon Vulnrichment

Updated: 2026-09-02T12:32:57.575Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:14.660

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:00:13Z

Weaknesses