What the vulnerability does
01Description
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
Explanation of Vulnerability in Simple Terms
YITH WooCommerce Gift Cards versions up to 3.19.0 allow unauthenticated attackers to upload arbitrary files to the site without restriction. An attacker can upload malicious files—including PHP scripts—over the network with no authentication required. This enables remote code execution and full site compromise.
What an attacker can do
Upload arbitrary files, including PHP scripts, to run code on the site.
Potential impact on your site
Attackers can upload malicious files and execute code, leading to complete site takeover.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities