---
id: CVE-2026-19439
title: >-
  The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does
  not have any authorisation check when displaying gift card details, allowing
  unauthenticated users to retrieve the gift cards attached to arbitrary orders
  and di…
summary: >-
  The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does
  not have any authorisation check when displaying gift card details, allowing
  unauthenticated users to retrieve the gift cards attached to arbitrary orders
  and di…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
product: Ultimate Gift Cards for WooCommerce
affected:
  - ultimate_gift_cards_for_woocommerce >= 3.0.3 < 3.2.10
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19439'
references:
  - url: 'https://wpscan.com/vulnerability/daefdabe-2277-4753-9df5-581134540000/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-10T13:08:20.470137Z'
ingestedAt: '2026-09-10T06:34:51.925Z'
epss: 0.00256
epssPercentile: 0.15393
---

## Overview

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend.

Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
