WooCommerce Plugin Vulnerability in Ultimate Gift Cards Allows Excess Store Credit
CVE-2026-19436

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-19436?

The Ultimate Gift Cards for WooCommerce plugin, prior to version 3.2.10, contains a vulnerability where it fails to properly match the issued gift card coupon values with the actual transaction amounts at checkout. This oversight allows unauthenticated users to exploit the system, effectively obtaining gift card credits that exceed their original payments. Such mismanagement of coupon values poses significant risks, enabling malicious actors to gain unauthorized financial advantages through the exploitation of gift card functionalities.

Affected Version(s)

Ultimate Gift Cards for WooCommerce 0 < 3.2.10

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guillermo Álvarez Fernández
WPScan
.