{"api_version":"1","generated_at":"2026-08-12T11:40:09+00:00","cve":"CVE-2026-15039","urls":{"html":"https://cve.report/CVE-2026-15039","api":"https://cve.report/api/cve/CVE-2026-15039.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-15039","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-15039"},"summary":{"title":"Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload","description":"The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-12 06:17:54","updated_at":"2026-08-12 06:17:54"},"problem_types":["CWE-434 Unrestricted Upload of File with Dangerous Type"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/b7b3308c-430e-4bc3-a3df-da20d47cf314/","name":"https://wpscan.com/vulnerability/b7b3308c-430e-4bc3-a3df-da20d47cf314/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-15039","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15039","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"giftware","version":"affected 4.2.10 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Brandon Steed","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"giftware","vendor":"Unknown","versions":[{"lessThan":"4.2.10","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Brandon Steed"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution."}],"problemTypes":[{"descriptions":[{"description":"CWE-434 Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T06:00:13.644Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/b7b3308c-430e-4bc3-a3df-da20d47cf314/"}],"source":{"discovery":"EXTERNAL"},"title":"Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-15039","datePublished":"2026-08-12T06:00:13.644Z","dateReserved":"2026-07-08T09:15:03.703Z","dateUpdated":"2026-08-12T06:00:13.644Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 06:17:54","lastModifiedDate":"2026-08-12 06:17:54","problem_types":["CWE-434 Unrestricted Upload of File with Dangerous Type"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"15039","Ordinal":"1","Title":"Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitr","CVE":"CVE-2026-15039","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"15039","Ordinal":"1","NoteData":"The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.","Type":"Description","Title":"Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitr"}]}}}