Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19439— Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details

Quick assessment

Affected
Unknown Ultimate Gift Cards for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

The Ultimate Gift Cards for WooCommerce WordPress 插件在 3.2.10 之前,在显示礼品卡详情时未进行任何身份验证检查,导致未认证用户可以获取任意订单关联的礼品卡,从而泄露客户个人数据、余额、日期;在 3.2.9 版本中还会泄露有效的兑换码(兑换码持有者可任意使用)。 从 3.0.3 到 3.2.8 的版本会泄露相同的数据,但不包含兑换码。

AI Predicted 5.3 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19439

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details
Source: CVE Program / CVE List V5
Vulnerability Description
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend. Versions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Ultimate Gift Cards for WooCommerce 3.0.3 ~ 3.2.10 -

II. Public POCs for CVE-2026-19439

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19439

登录查看更多情报信息。

Security Blog Posts for CVE-2026-19439 (1)

Same Patch Batch · Unknown · 2026-09-10 · 8 CVEs total

CVE-2026-82925 Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature
CVE-2026-81431 Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un
CVE-2026-77770 miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em
CVE-2026-77771 miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
CVE-2026-78361 zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio
CVE-2026-19840 Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions
CVE-2026-19436 Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v

IV. Related Vulnerabilities

V. Comments for CVE-2026-19439

No comments yet


Leave a comment