CVE-2026-75861
Deferred Deferred - Pending Action

Unauthorized Gift Card Redemption in Ultimate Gift Cards for WooCommerce

Vulnerability report for CVE-2026-75861, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: WPScan

Description

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In 3.2.9 an ownership check was added on one of the two affected redemption paths; the one that remains requires a companion Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 from the same vendor to be active.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ultimate_gift_cards ultimate_gift_cards_for_woocommerce to 3.2.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Ultimate Gift Cards for WooCommerce WordPress plugin before version 3.2.10. It allows any authenticated user, including low-privilege subscribers, to redeem gift cards belonging to other users without proper authorization. The attacker's actions zero out the victim's gift card balance while crediting the value to themselves. The issue occurs due to insufficient verification of gift card ownership during redemption.

Detection Guidance

Check if the Ultimate Gift Cards for WooCommerce plugin is installed and verify its version. If the version is below 3.2.10, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details.

Impact Analysis

If you use the affected plugin version, an attacker could steal gift card balances from other users. Victims lose their gift card value while attackers gain unauthorized credits. This could lead to financial losses for users and reputational damage for the plugin or store owners.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by enabling unauthorized access to user gift card balances, which may involve processing personal financial data without proper authorization. Unauthorized redemption could lead to financial losses for users, raising concerns about data integrity and security controls required by these regulations.

Mitigation Strategies

Update the Ultimate Gift Cards for WooCommerce plugin to version 3.2.10 or later immediately. If using a companion plugin, ensure it is also updated. Revoke any unauthorized gift card redemptions and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75861. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart