CVE-2026-45444Active Exploitation

LOWCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-21: 3Active Exploitation · 2026-05-21: 1Technical Details · 2026-05-21: 205-21
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2026-45444 WordPress Gift Cards For WooCommerce Pro Plugin <= 4.2.6 is vulnerable to a high priority Arbitrary File Upload https://patchstack.com/database/wordpress/plugin/giftware/vulnerability/wordpress-gift-cards-for-woocommerce-pro-plugin-4-2-6-arbitrary-file-upload-vulnerability?_s_id=cve

    Post summary

    CVE‑2026‑45444 is a newly disclosed high‑priority arbitrary file upload vulnerability affecting WordPress Gift Cards For WooCommerce Pro plugin 4.2.6 and earlier. The tweet does not provide a PoC, exploit, or patch details.

    00010324
    6.9K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Active Exploitation

    CVE-2026-45444 (WP Swings Gift Cards For WooCommerce Pro) is a critical, unrestricted exploitation, with confirmed in-wild exploitation. See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-20/TIER_1_CVE-2026-45444.md #CyberSecurity #DPI #WordPress #WooCommerce #WebSecurity

    Post summary

    CVE-2026-45444, a critical vulnerability in WP Swings Gift Cards for WooCommerce Pro, has confirmed in‑the‑wild exploitation as documented in the linked GitHub report.

    0001065
    46 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45444 Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45444

    Post summary

    The statement identifies CVE‑2026‑45444 as an unrestricted file upload flaw in a WordPress plugin but provides no concrete PoCs, exploitation details, or patch information.

    0000073
    4.0K followersView on X

Explore more