CVE-2026-84760: WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access Control vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
Affected Software
1 affected component
Ultimate Gift Cards For WooCommerce<=3.2.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Gift Cards For WooCommerce pluginto a version that resolves this vulnerability.Fixed in 3.2.10
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges to exploit the affected plugin.
2
What versions should be treated as affected?
Ultimate Gift Cards For WooCommerce versions 3.2.9 and earlier are identified as affected.
3
What is the reported impact?
The supplied severity vector indicates low confidentiality impact, with no reported integrity or availability impact. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.