First published: Mon Dec 28 2020(Updated: )
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce Gift Cards | =3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this file upload vulnerability is CVE-2020-35627.
The affected software is Ultimate WooCommerce Gift Cards version 3.0.2.
The severity of CVE-2020-35627 is high with a CVSS score of 8.8.
This vulnerability occurs due to a file upload vulnerability in the Custom GiftCard Template of Ultimate WooCommerce Gift Cards.
An attacker can exploit this vulnerability by uploading a custom image with a malicious code, which can then be executed remotely.