Impact
The vulnerability is an unauthenticated broken access control that allows attackers to manipulate gift card records in the WordPress Ultimate Gift Cards For WooCommerce plugin without authenticating as a privileged user. This could let attackers create, edit, or delete gift cards, altering their values or generating fraudulent discounts or unauthorized payouts. The weakness corresponds to CWE‑862, which defines authorization check failures.
Affected Systems
All WordPress sites that have installed the WP Swings Ultimate Gift Cards For WooCommerce plugin at version 3.2.9 or earlier are affected. The issue is confined to the plugin component and does not extend to other WordPress core or plugin code. Site administrators should check the plugin version and upgrade if necessary.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is through the plugin’s administrative endpoints accessed via the web interface. The CVSS score of 5.3 indicates moderate risk, and the absence of a KEV listing does not imply low threat. EPSS information is not available, but the nature of the flaw suggests the exploitation probability may be significant in environments where the plugin’s admin URLs are reachable from the internet. An attacker would need to discover the plugin’s management endpoints, then issue requests to create, edit or delete gift cards, potentially generating fraudulent discounts or unauthorized payouts.
OpenCVE Enrichment