S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Sep 10, 2025

CVE-2024-8425 Scanner

CVE-2024-8425 Scanner - Arbitrary File Upload vulnerability in WooCommerce Ultimate Gift Card

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8425
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added. The only patched version we have confirmed is 2.9.3.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WooCommerce Ultimate Gift Cardby WP Swings
0
Updated Aug 19, 2026View on NVD →
Detail

The WooCommerce Ultimate Gift Card plugin is widely used by e-commerce sites running on WordPress to offer gift cards to consumers. It is a popular choice for online stores to enhance customer satisfaction and boost sales by providing an easy way to purchase and redeem gift cards. The plugin is utilized by store owners and administrators to manage gift card creation, sales, and distribution effectively. Its features include customizable gift card templates and integration with WooCommerce, making it versatile for various store types. With a vast user base, the security of this plugin is critical to maintaining trust and ensuring smooth operations. This scanner focuses on identifying vulnerabilities that could jeopardize e-commerce transactions and user information.

The vulnerability detected in the WooCommerce Ultimate Gift Card plugin pertains to arbitrary file uploads. This occurs due to insufficient file type validation in certain functions, specifically 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data'. Unauthenticated attackers can exploit this vulnerability to upload arbitrary files to the server. These malicious files can lead to remote code execution, allowing attackers to manipulate the server's operations maliciously. The impact of such a breach could be significant, compromising the security and functionality of affected e-commerce sites using this plugin. Accurately detecting and mitigating this vulnerability is crucial to protecting user data and site integrity.

Technical aspects of this vulnerability involve the failure to properly validate file types before upload. Vulnerable endpoints such as '/wp-admin/admin-ajax.php?action=mwb_wgm_preview_mail' can be exploited by submitting multipart/form-data requests. This allows the upload of files with any extension, which is then stored in the server's directories. The vulnerability can be confirmed by checking the server's response for unauthorized files, ensuring the attack's payload is correctly uploaded. Successful exploitation typically manifests when attackers bypass the assumed security measures to upload harmful scripts or programs onto the server, often without user authentication. Identifying these weaknesses is crucial for effective vulnerability management.

If exploited, this vulnerability can result in severe consequences for affected e-commerce platforms. Attackers may gain unauthorized access to the server, leading to potential data breaches involving sensitive customer information and transaction details. There is also a risk of remote code execution, which could allow attackers to control server operations, deploy malware, or disrupt services. Such an attack could damage business reputation, incur financial losses, and result in legal repercussions. It is vital for administrators to address this vulnerability promptly to prevent exploitation and safeguard their online platforms and user data effectively.

REFERENCES

Solution Advice
  • Immediately update the WooCommerce Ultimate Gift Card plugin to its latest version to address the vulnerability.
  • Implement strict file type validation mechanisms to prevent arbitrary file uploads.
  • Conduct regular security audits of the website's plugin to identify and fix vulnerabilities promptly.
  • Utilize a security plugin or firewall on WordPress sites to further shield against unauthorized file uploads.
  • Ensure server permissions are properly configured to thwart unauthorized file execution.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-8425 Scanner - Arbitrary File Upload vulnerability in WooCommerce Ultimate Gift Card S4E