Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-15039: WooCommerce Gift Cards < 4.2.10 Allows Unwanted File Uploads
CVE-2026-15039 · published 1 month ago
Summary
A security issue in WooCommerce Gift Cards allows hackers to upload any file, potentially including malicious code, without needing a password. This could lead to unauthorized access to your website. To protect your site, update WooCommerce Gift Cards to version 4.2.10 or later.
What to do
- Update unknown giftware to version 4.2.10 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | giftware | < 4.2.10 |
Original advisory text
Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-434Unrestricted File Upload
Timeline
Published12 Aug 2026
Updated1 Oct 2026
First seen12 Aug 2026
Track software like this
Free during beta