CVE-2026-19436: CWE-284 Improper Access Control in Ultimate Gift Cards for WooCommerce
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
AI Analysis
Technical Summary
CVE-2026-19436 is an improper access control vulnerability (CWE-284) in the Ultimate Gift Cards for WooCommerce plugin for WordPress. Versions prior to 3.2.10 do not properly verify that the value of gift card coupons issued matches the amount collected at checkout. This allows unauthenticated attackers to generate store credit beyond their legitimate payment, potentially leading to financial loss for the store.
Potential Impact
Unauthenticated attackers can exploit this vulnerability to obtain more store credit than they paid for, effectively allowing unauthorized financial gain and potential revenue loss for affected e-commerce stores using the vulnerable plugin versions.
Mitigation Recommendations
No official patch or remediation guidance is currently provided. Users should upgrade to version 3.2.10 or later once available, as the vulnerability affects versions before 3.2.10. Until a fix is confirmed, restrict access to the plugin or disable it if possible to prevent exploitation. Monitor vendor advisories for official updates.
CVE-2026-19436: CWE-284 Improper Access Control in Ultimate Gift Cards for WooCommerce
Description
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
CVSS v3.1
Score 7.5high
Affected software
Ultimate Gift Cards for WooCommerce
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-19436 is an improper access control vulnerability (CWE-284) in the Ultimate Gift Cards for WooCommerce plugin for WordPress. Versions prior to 3.2.10 do not properly verify that the value of gift card coupons issued matches the amount collected at checkout. This allows unauthenticated attackers to generate store credit beyond their legitimate payment, potentially leading to financial loss for the store.
Potential Impact
Unauthenticated attackers can exploit this vulnerability to obtain more store credit than they paid for, effectively allowing unauthorized financial gain and potential revenue loss for affected e-commerce stores using the vulnerable plugin versions.
Mitigation Recommendations
No official patch or remediation guidance is currently provided. Users should upgrade to version 3.2.10 or later once available, as the vulnerability affects versions before 3.2.10. Until a fix is confirmed, restrict access to the plugin or disable it if possible to prevent exploitation. Monitor vendor advisories for official updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-10T12:44:06.866Z
- State
- PUBLISHED
Threat ID: 6aa25043acd9273b49ac4bb1
Added to database: 09/10/2026, 06:37:55 UTC
Last enriched: 09/10/2026, 06:53:47 UTC
Last updated: 09/10/2026, 22:17:09 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.