Skip to main content
QUIETLYTIC
Vulnerability

Gift Cards For WooCommerce Pro Vulnerability (CVE-2026-15039)

CVE-2026-15039 is a CVSS 9.8 unrestricted file upload flaw in a WooCommerce gift-card plugin allowing unauthenticated RCE, reported exploited by VulnCheck.

CVE-2026-15039
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Gift Cards For WooCommerce Pro, WP Swings Gift Cards For WooCommerce Pro (before 4.2.10)

CVE-2026-15039 carries a CVSS 3.1 base score of 9.8 against Gift Cards For WooCommerce Pro, a WordPress plugin published by WP Swings for selling gift cards on WooCommerce stores. NVD’s description refers to the plugin by its internal slug, “giftware,” and states the flaw is fixed in version 4.2.10, meaning all earlier versions are affected. NVD classifies it as CWE-434 (Unrestricted Upload of File with Dangerous Type). VulnCheck’s KEV feed reports the CVE as exploited, dated August 21, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-15039 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description is direct: the plugin does not validate the type of uploaded files in one of its upload paths, and this omission allows unauthenticated users to upload arbitrary files, including PHP code. Unrestricted file upload of this kind is one of the more severe vulnerability classes because, unlike many injection or logic flaws, a successfully uploaded PHP file typically grants direct code execution the moment it’s requested — there is no separate step an attacker needs to chain afterward.

NVD’s description does not specify which upload endpoint lacks the type check, only that it exists somewhere in the plugin’s upload handling. This is a gap in the publicly available technical detail, which we report rather than fill with speculation about which specific form or AJAX action is responsible.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-434 classification, and the fixed version (4.2.10) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00569, a 45.6th percentile score as of our ingestion.

No field is in conflict between our two sources.

Why this matters

Unauthenticated arbitrary file upload leading to remote code execution is among the most severe outcomes a WordPress vulnerability can produce, on par with the most critical flaws we’ve covered in this batch: it requires no credential, no social engineering, and no chained secondary bug — a single request against the vulnerable upload path can result in full code execution on the hosting server. A gift-card plugin is a common and often overlooked component on e-commerce sites, precisely the kind of dependency an operator might not prioritize checking against a CVE feed the way they would a more central piece of infrastructure.

Because the fix is a straightforward version upgrade with a clearly stated boundary (4.2.10), remediation is unambiguous once a site operator identifies that the plugin is installed and outdated.

Frequently Asked Questions

What is CVE-2026-15039? A CVSS 9.8 unrestricted file upload vulnerability (CWE-434) in the Gift Cards For WooCommerce Pro WordPress plugin (NVD refers to it internally by its “giftware” plugin slug), fixed in version 4.2.10, allowing unauthenticated attackers to upload PHP files and achieve remote code execution.

Is CVE-2026-15039 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 21, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Which upload path is vulnerable? NVD’s description does not name the specific upload endpoint, only that type validation is missing in one of the plugin’s upload paths. We report this gap rather than speculate about which one.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Version 4.2.10, per NVD.


Severity, vector, weakness classification, and fixed version sourced from the National Vulnerability Database record for CVE-2026-15039. Exploitation status and the August 21, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools