Insecure Gift Card Redemption in Ultimate Gift Cards Plugin for WooCommerce by WordPress
CVE-2026-75861

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-75861?

The Ultimate Gift Cards for WooCommerce WordPress plugin lacks a robust mechanism to ensure that gift card redemptions are performed by the rightful recipients. This vulnerability permits any authenticated user, including subscribers, to redeem gift cards that belong to other users. As a result, the balance of the compromised gift cards may be depleted, and their value credited to the unauthorized user instead. An ownership validation check was introduced in version 3.2.9 for one redemption method, but the other method remains unprotected unless used with a compatible version of the plugin. This oversight allows for potential exploitation, highlighting the need for prompt updates and vigilant security practices.

Affected Version(s)

Ultimate Gift Cards for WooCommerce 0 < 3.2.10

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shikhali Jamalzade
WPScan
.