Unrated severityNVD Advisory· Published Sep 9, 2026
CVE-2026-75861
CVE-2026-75861
Description
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves.
In 3.2.9 an ownership check was added on one of the two affected redemption paths; the one that remains requires a companion Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 from the same vendor to be active.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.2.10+ 1 more
- (no CPE)range: <3.2.10
- (no CPE)range: <3.2.10
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.