Description
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files.

This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.
Published: 2026-05-20
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an unrestricted upload of files with dangerous types that exists in the Gift Cards For WooCommerce Pro plugin. The plugin does not validate the file type for uploads, which allows an attacker to place a file containing malicious code—such as a PHP script—onto the WordPress server. While the CVE entry does not state that the uploaded file will automatically be executed, the nature of the arbitrary file upload combined with the availability of a script file implies a high likelihood that, once accessible, the file could be executed in the web context, providing the attacker with remote code execution capabilities.

Affected Systems

WP Swings Gift Cards For WooCommerce Pro is affected in all releases up through version 4.2.6; no later release is known to contain a fix.

Risk and Exploitability

With a CVSS score of 10, the vulnerability is classified as critical. The absence of EPSS data makes it difficult to gauge real‑world exploitation frequency, but the high base score and lack of hardening measures suggest the risk is significant. The attack vector is likely through the plugin’s file upload interface: an attacker could either use the configuration page accessible to administrators or potentially submit a file via a publicly exposed upload endpoint if the plugin does not require authentication. Because the flaw allows uploading dangerous file types, the potential impact includes remote code execution, data exfiltration, and full site compromise. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on May 20, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gift Cards For WooCommerce Pro to a version newer than 4.2.6, which removes the unrestrained file upload capability.
  • If an upgrade is not immediately possible, disable the plugin’s file upload feature or deactivate the plugin entirely to eliminate the attack surface.
  • While waiting for the upgrade, restrict WordPress upload MIME types to disallow PHP and other executable extensions, ensuring that even if a file is uploaded it cannot be executed.

Generated by OpenCVE AI on May 20, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 20 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.
Title WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-20T18:00:51.131Z

Reserved: 2026-05-12T13:08:41.670Z

Link: CVE-2026-45444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-20T20:16:40.680

Modified: 2026-05-20T20:16:40.680

Link: CVE-2026-45444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T21:45:40Z

Weaknesses