Insecure Gift Card Redemption in Ultimate Gift Cards Plugin for WooCommerce by WordPress
CVE-2026-75861
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-75861?
The Ultimate Gift Cards for WooCommerce WordPress plugin lacks a robust mechanism to ensure that gift card redemptions are performed by the rightful recipients. This vulnerability permits any authenticated user, including subscribers, to redeem gift cards that belong to other users. As a result, the balance of the compromised gift cards may be depleted, and their value credited to the unauthorized user instead. An ownership validation check was introduced in version 3.2.9 for one redemption method, but the other method remains unprotected unless used with a compatible version of the plugin. This oversight allows for potential exploitation, highlighting the need for prompt updates and vigilant security practices.
Affected Version(s)
Ultimate Gift Cards for WooCommerce 0 < 3.2.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.