CVE-2026-19439: Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend.
Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ultimate Gift Cards for WooCommerce WordPress pluginto a version that resolves this vulnerability.Fixed in 3.2.10 - Compensating control
Restrict access to the wps_uwgc_report_details endpoint/route so unauthenticated users cannot retrieve gift card details (customer PII, balances, dates, and in versions up to 3.2.9 the live redemption code).
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated gift-card theft rather than data disclosure alone?
Version 3.2.9 exposes the live redemption code along with customer data, balances, and dates; anyone who obtains that code can spend the associated gift card. Versions 3.0.3 through 3.2.8 disclose the other gift-card and customer information but not the redemption code.
What does an attacker need to exploit this issue?
No authentication is required. An attacker can retrieve gift-card details for arbitrary orders because the affected functionality lacks an authorization check.
What version remediates the issue?
Upgrade to version 3.2.10 or later. The issue affects versions before 3.2.10.