---
id: CVE-2026-19436
title: >-
  The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does
  not reconcile the value of the gift card coupon it issues against the amount
  actually collected at checkout, allowing unauthenticated users to obtain store
  credi…
summary: >-
  The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does
  not reconcile the value of the gift card coupon it issues against the amount
  actually collected at checkout, allowing unauthenticated users to obtain store
  credi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-284
product: Ultimate Gift Cards for WooCommerce
affected:
  - ultimate_gift_cards_for_woocommerce < 3.2.10
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19436'
references:
  - url: 'https://wpscan.com/vulnerability/7c2f56f6-9c0a-4de2-9cd2-9c25a25c3530/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T13:08:05.462463Z'
ingestedAt: '2026-09-10T06:34:51.925Z'
epss: 0.00208
epssPercentile: 0.09741
---

## Overview

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
