VYPR

Giftware

by WordPress

CVEs (2)

  • CVE-2026-45444CriMay 20, 2026
    risk 0.65cvss 10.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

  • CVE-2026-15039CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.