CVE-2026-15039

CVE-2026-15039: Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload

Vendor Unknown
Product giftware
Published August 12, 2026
Last update August 12, 2026

CVSS base score

What the vulnerability does

01Description

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.

Key dates

02Disclosure timeline

August 12, 2026 CVE published
August 12, 2026 Record updated