CVE-2024-8425 is a critical arbitrary file upload vulnerability affecting all versions up to and including 2.6.0 of the WooCommerce Ultimate Gift Card plugin for WordPress. This flaw, due to insufficient file type validation, allows unauthenticated attackers to upload malicious files to the server. With a CVSS score of 9.8 (CRITICAL), the vulnerability can lead to remote code execution, compromising the entire system. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist, indicating potential for exploit development. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.0CPE matchmatch criteria | cpe:2.3:a:wpswings:woocommerce_ultimate_gift_card:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.