CVE-2024-8425

CRITICAL EXPLOITED NUCLEI

WooCommerce Ultimate Gift Card <2.6.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-8425 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including KTN1990. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets CVE-2024-8425, an unauthenticated arbitrary file upload vulnerability in the WooCommerce Ultimate Gift Card WordPress plugin (versions <= 2.6.0). It uploads a PHP shell via the 'mwb_wgm_preview_mail' endpoint and verifies successful upload by checking for a specific string in the response.

Description

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added. The only patched version we have confirmed is 2.9.3.

Exploits (1)

nomisec WORKING POC 2 stars
by KTN1990 · remote
https://github.com/KTN1990/CVE-2024-8425

This exploit targets CVE-2024-8425, an unauthenticated arbitrary file upload vulnerability in the WooCommerce Ultimate Gift Card WordPress plugin (versions <= 2.6.0). It uploads a PHP shell via the 'mwb_wgm_preview_mail' endpoint and verifies successful upload by checking for a specific string in the response.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WooCommerce Ultimate Gift Card <= 2.6.0
No auth needed
Prerequisites: Python 3 · list of target URLs
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload
CRITICALVERIFIEDby jsnv-dev
FOFA: body="/wp-content/plugins/woocommerce-ultimate-gift-card"

Scores

CVSS v3 9.8
EPSS 0.0386
EPSS Percentile 88.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-02-27
CWE
CWE-434
Status published
Products (2)
WP Swings/WooCommerce Ultimate Gift Card < 2.9.2
wpswings/woocommerce_ultimate_gift_card < 2.6.0
Published Feb 28, 2025
Tracked Since Feb 18, 2026