Feed/CVE-2026-15039
CVE-2026-15039

CVE-2026-15039

Published Aug 12, 2026·Updated Aug 12, 2026

NVD Description

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free