Junglewise Threat Intelligence

CVE-2026-84760: Ultimate Gift Cards For WooCommerce broken access control

CVE-2026-84760 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Vendors: WooCommerce.

Executive brief

Ultimate Gift Cards For WooCommerce is a WordPress plugin that allows customers to purchase and manage gift cards in WooCommerce stores. The plugin contains an unauthenticated broken access control vulnerability that allows attackers to access pages and perform actions they should not be permitted to, potentially viewing other customers' gift card data or manipulating gift card operations without proper authorization.

Technical details

The vulnerability is a broken access control flaw in Ultimate Gift Cards For WooCommerce versions up to 3.2.9 that permits unauthenticated access to sensitive functionality. The flaw allows attackers to bypass authorization checks and access or modify gift card data belonging to other users without proper authentication or privilege verification. No special authentication or user privileges are required to exploit this issue; the attack vector is network-based. The vulnerability has been patched in version 3.2.10 and later.

Affected products

  • WooCommerce Ultimate Gift Cards For WooCommerce up to 3.2.9

Timeline

  • 2026-08-02: disclosed: Reported by Uma Mo
  • 2026-09-02: advisory: Published by Patchstack
  • 2026-09-02: patched: Fixed in version 3.2.10

References