Unrated severityNVD Advisory· Published Sep 10, 2026
CVE-2026-19439
CVE-2026-19439
Description
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend.
Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.2.10, 3.0.3-3.2.8
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.