What the vulnerability does
01Description
The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the wps_wgm_preview_email_template(). This makes it possible for unauthenticated attackers to read password protected and draft posts that may contain sensitive data.
Explanation of Vulnerability in Simple Terms
02Summary
The Ultimate Gift Cards for WooCommerce plugin through version 2.6.6 lacks proper authorization checks, allowing unauthenticated attackers to read sensitive data. An attacker can access information without logging in or requiring user interaction. This affects all installations running the vulnerable version.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site without authentication.
Potential impact on your site
04Site Impact
Unauthenticated visitors can access sensitive information exposed by the plugin.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 16, 2024
CVE published
April 8, 2026
Record updated