CVE-2026-15039 PUBLISHED

Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload

Assigner: WPScan
Reserved: 08.07.2026 Published: 12.08.2026 Updated: 12.08.2026

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.

Product Status

Vendor Unknown
Product giftware
Versions Default: unaffected
  • affected from 0 to 4.2.10 (excl.)

Credits

  • Brandon Steed finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE