What the vulnerability does
01Description
The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances without purchasing anything.
Explanation of Vulnerability in Simple Terms
02Summary
Gift Cards for WooCommerce Pro versions up to 2.9.1 lack proper authorization checks, allowing unauthenticated attackers to modify gift card data. An attacker can change gift card values, balances, or status without needing to log in or interact with a user. This affects all WooCommerce sites running the vulnerable plugin.
What an attacker can do
03Attacker Capabilities
Modify or tamper with gift card records, including balances and validity, without authentication.
Potential impact on your site
04Site Impact
Gift card fraud: attackers can increase card balances, extend expiration dates, or invalidate legitimate cards.
Conditions required to exploit
05Prerequisites
Network access to the site; no login or user interaction required.
Key dates
06Disclosure timeline
January 8, 2025
CVE published
May 20, 2026
Record updated