CVE-2024-8425
CRITICAL EXPLOITED NUCLEIWooCommerce Ultimate Gift Card <2.6.0 - RCE
Title source: llmDescription
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added. The only patched version we have confirmed is 2.9.3.
Exploits (1)
Nuclei Templates (1)
WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload
CRITICALVERIFIEDby jsnv-dev
FOFA:
body="/wp-content/plugins/woocommerce-ultimate-gift-card"
Scores
CVSS v3
9.8
EPSS
0.4508
EPSS Percentile
97.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-02-27
CWE
CWE-434
Status
published
Products (2)
WP Swings/WooCommerce Ultimate Gift Card
< 2.9.2
wpswings/woocommerce_ultimate_gift_card
< 2.6.0
Published
Feb 28, 2025
Tracked Since
Feb 18, 2026