Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload
Summary
| CVE | CVE-2026-15039 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 06:17:54 UTC |
| Updated | 2026-08-12 06:17:54 UTC |
| Description | The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution. |
Risk And Classification
Problem Types: CWE-434 Unrestricted Upload of File with Dangerous Type
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/b7b3308c-430e-4bc3-a3df-da20d47cf314 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Brandon Steed (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.