Executive brief
WP Swings Gift Cards For WooCommerce Pro, a WordPress plugin used to manage digital gift cards, contains a critical security flaw that allows unauthorized users to upload files to the server. An attacker can use this to upload malicious scripts, potentially taking full control of the website, stealing customer data, or disrupting business operations. As of the latest report, there is no official patch available from the developer.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the WP Swings Gift Cards For WooCommerce Pro plugin for WordPress through version 4.2.6. The flaw allows an unauthenticated remote attacker to upload files with dangerous extensions (such as .php) to the web server. Because the plugin fails to properly validate file types or origins, an attacker can achieve remote code execution (RCE) by accessing the uploaded malicious file. This vulnerability has a CVSS score of 10.0 due to the lack of required authentication and the high impact on confidentiality, integrity, and availability. No official patch has been released yet.
Affected products
- WP Swings Gift Cards For WooCommerce Pro <= 4.2.6
Timeline
- 2026-05-19: other: Reported by Joe Bruno (Monarx)
- 2026-05-20: advisory: Published by Patchstack and NVD