Junglewise Threat Intelligence

CVE-2026-19439: Ultimate Gift Cards for WooCommerce authorization bypass

CVE-2026-19439 · Severity: high · CVSS 7.5 · Published 2026-09-10

Vendors: WPScan.

Executive brief

The Ultimate Gift Cards for WooCommerce WordPress plugin lacks proper access controls when displaying gift card details, allowing anyone on the internet to view sensitive customer information including personal data, gift card balances, and redemption codes without logging in. An attacker could retrieve this information for any order by manipulating API parameters, potentially using the live redemption codes to spend gift cards or selling the stolen customer data to third parties.

Technical details

The plugin fails to implement authorization checks in the wps_uwgc_report_details endpoint, allowing unauthenticated users to retrieve gift card details for arbitrary orders. The vulnerability affects versions 3.0.3 through 3.2.9, with versions 3.2.9 disclosing the live redemption code (which can be immediately spent) and earlier versions disclosing customer PII, balances, and dates without the code. The attack requires no authentication or special preconditions—an attacker need only craft HTTP requests with varying order identifiers. The vulnerability has been patched in version 3.2.10.

Affected products

  • WPScan Ultimate Gift Cards for WooCommerce 3.0.3 to 3.2.9

Timeline

  • 2026-09-08: disclosed
  • 2026-09-10: patched: Fixed in version 3.2.10

References