CVE-2026-15039: Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload
Published Aug 12, 2026
·Updated
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.
Affected Software
1 affected component
Giftware WordPress plugin Gift Cards for WooCommerce Pro<4.2.10
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-15039?
CVE-2026-15039 has a severity rating of 92, indicating a critical risk.
2
How do I fix CVE-2026-15039?
To fix CVE-2026-15039, update the Gift Cards for WooCommerce Pro plugin to version 4.2.10 or later.
3
What is CVE-2026-15039?
CVE-2026-15039 is a vulnerability in the Gift Cards for WooCommerce Pro plugin that allows unauthenticated arbitrary file uploads.
4
What are the potential impacts of CVE-2026-15039?
The potential impact of CVE-2026-15039 includes remote code execution through uploaded malicious PHP files.
5
Who is affected by CVE-2026-15039?
CVE-2026-15039 affects users running versions of the Gift Cards for WooCommerce Pro plugin before 4.2.10.