{"api_version":"1","generated_at":"2026-09-10T09:14:28+00:00","cve":"CVE-2026-19439","urls":{"html":"https://cve.report/CVE-2026-19439","api":"https://cve.report/api/cve/CVE-2026-19439.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-19439","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-19439"},"summary":{"title":"Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details","description":"The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend.\n\nVersions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-10 07:17:02","updated_at":"2026-09-10 07:17:02"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/daefdabe-2277-4753-9df5-581134540000/","name":"https://wpscan.com/vulnerability/daefdabe-2277-4753-9df5-581134540000/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19439","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19439","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Ultimate Gift Cards for WooCommerce","version":"affected 3.0.3 3.2.10 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Usama Arshad","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Ultimate Gift Cards for WooCommerce","vendor":"Unknown","versions":[{"lessThan":"3.2.10","status":"affected","version":"3.0.3","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Usama Arshad"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend.\n\nVersions from 3.0.3 to 3.2.8 disclose the same data without the redemption code."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-10T06:00:05.700Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/daefdabe-2277-4753-9df5-581134540000/"}],"source":{"discovery":"EXTERNAL"},"title":"Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-19439","datePublished":"2026-09-10T06:00:05.700Z","dateReserved":"2026-08-10T13:02:17.334Z","dateUpdated":"2026-09-10T06:00:05.700Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-10 07:17:02","lastModifiedDate":"2026-09-10 07:17:02","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"19439","Ordinal":"1","Title":"Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthentica","CVE":"CVE-2026-19439","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"19439","Ordinal":"1","NoteData":"The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption code, which anyone holding it can spend.\n\nVersions from 3.0.3 to 3.2.8 disclose the same data without the redemption code.","Type":"Description","Title":"Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthentica"}]}}}