SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19436

HIGH · CVSS 7.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Ultimate Gift Cards for WooCommerce plugin for WordPress versions prior to 3.2.10 is vulnerable as it fails to validate the value of gift card coupons against the actual transaction amount, enabling unauthenticated users to exploit this flaw and receive store credit exceeding their payment. This vulnerability poses a significant risk to e-commerce sites using the plugin, as it can lead to financial losses through unauthorized credit issuance. WordPress site administrators utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-19436
Severity
HIGH
CVSS
7.5
EPSS
0.21%
WordPress

Original NVD Description

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.