CVE-2024-11423 HIGH

CVE-2024-11423: Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

Vendor Wp Swings
Product Gift Cards for WooCommerce Pro
Weakness CWE-862 · Missing authorization
Published January 8, 2025
Last update May 20, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances without purchasing anything.

Explanation of Vulnerability in Simple Terms

02Summary

Gift Cards for WooCommerce Pro versions up to 2.9.1 lack proper authorization checks, allowing unauthenticated attackers to modify gift card data. An attacker can change gift card values, balances, or status without needing to log in or interact with a user. This affects all WooCommerce sites running the vulnerable plugin.

What an attacker can do

03Attacker Capabilities

Modify or tamper with gift card records, including balances and validity, without authentication.

Potential impact on your site

04Site Impact

Gift card fraud: attackers can increase card balances, extend expiration dates, or invalidate legitimate cards.

Conditions required to exploit

05Prerequisites

Network access to the site; no login or user interaction required.

Key dates

06Disclosure timeline

January 8, 2025 CVE published
May 20, 2026 Record updated

Related vulnerabilities

08Related CVE