← back
CVE-2026-45444criticalobserved exploitationCWE-434

WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upload vulnerability

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 10epss 0.3%
from disclosure to weapon
Published on NVDMay 20
VulnCheckMay 20
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
yesVulnCheck
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H