WooCommerce Plugin Vulnerability in Ultimate Gift Cards Allows Excess Store Credit
CVE-2026-19436
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2026
Badges
What is CVE-2026-19436?
The Ultimate Gift Cards for WooCommerce plugin, prior to version 3.2.10, contains a vulnerability where it fails to properly match the issued gift card coupon values with the actual transaction amounts at checkout. This oversight allows unauthenticated users to exploit the system, effectively obtaining gift card credits that exceed their original payments. Such mismanagement of coupon values poses significant risks, enabling malicious actors to gain unauthorized financial advantages through the exploitation of gift card functionalities.
Affected Version(s)
Ultimate Gift Cards for WooCommerce 0 < 3.2.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.