What is CVE-2026-15039?
CVE-2026-15039 is a vulnerability in the Giftware WordPress plugin (versions before 4.2.10) where a lack of file type validation in an upload path allows unauthenticated users to upload arbitrary files, including PHP code, potentially leading to Remote Code Execution (RCE).
Azərbaycanca: CVE-2026-15039, Giftware WordPress plaginində (4.2.10-dan əvvəlki versiyalar) fayl yükləmə funksiyasında tip doğrulamasının olmaması səbəbindən autentifikasiya olunmamış istifadəçilərə PHP kodu da daxil olmaqla ixtiyari fayl yükləməyə imkan verir ki, bu da uzaqdan kod icrasına (RCE) yol aça bilər.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which plugin and versions are affected by CVE-2026-15039?
CVE-2026-15039 affects the Giftware WordPress plugin versions before 4.2.10.
What can an unauthenticated attacker achieve by exploiting CVE-2026-15039?
An unauthenticated attacker can upload arbitrary files, including PHP code, potentially leading to Remote Code Execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.