← Back to CVE List

CVE-2020-35627

Published: 2020-12-28T15:15Z
Last Modified: 2024-11-21T05:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary code. Once it contains the function "Custom Gift Card Template", the function of uploading a custom image is used, changing the name of the image extension to PHP and executing PHP code on the server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt