Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] <= 3.2.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Gift Cards For WooCommerce: from n/a through <= 3.2.4.
- Affected:
- up to 3.2.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-24375 on NVD →
Ultimate Gift Cards for WooCommerce <= 3.2.4 - Missing Authorization
medium
The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.5
- Disclosed:
- Jan 8, 2026
CVE-2026-24375 on NVD →
Ultimate Gift Cards for WooCommerce <= 3.1.4 - Authenticated (Administrator+) SQL Injection via wps_wgm_save_post Function
medium
The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'default_price' and 'product_id' parameters in all versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...
- CVSS:
- 4.9
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Jun 2, 2025
CVE-2025-5103 on NVD →
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 3.0.7
unknown
[en] The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.7
- Disclosed:
- Jan 8, 2025
CVE-2024-11423 on NVD →
Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch
high
The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...
- CVSS:
- 7.5
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.7
- Disclosed:
- Jan 7, 2025
CVE-2024-11423 on NVD →
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 2.6.7
unknown
[en] The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the wps_wgm_preview_email_template(). This makes it possible for unauthenticat...
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Mar 16, 2024
CVE-2024-1857 on NVD →
Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information Exposure
medium
The Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the wps_wgm_preview_email_template(). This makes it possible for unauthenticated at...
- CVSS:
- 5.3
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Mar 15, 2024
CVE-2024-1857 on NVD →
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 2.1.2
unknown
[en] The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift car...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jul 1, 2023
CVE-2021-4391 on NVD →
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 2.1.2
unknown
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Ultimate Gift Cards for WooCommerce <= 2.1.1 - Cross-Site Request Forgery Bypass
medium
The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card det...
- CVSS:
- 4.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Jun 21, 2021
CVE-2021-4391 on NVD →
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 2.1.2
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Ultimate Gift Cards For WooCommerce plugin (versions <= 2.1.1).
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jun 21, 2021
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 2.1.2
unknown
Multiple plugins are affected by CSRF bypass as they do not properly check for the nonce due to a logic flaw. This could allow attackers to make logged in users do unwanted actions
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 2.1.2
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
Ultimate Gift Cards for WooCommerce [woo-gift-cards-lite] < 3.1.5
unknown
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
CVE-2025-5103 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database