Hackers are actively targeting a critical flaw in YITH WooCommerce Gift Cards Premium, a WordPress plugin used on over 50,000 websites. The vulnerability allows unauthenticated attackers to upload files to vulnerable sites, including web shells that provide full access to the site.
The vulnerability was disclosed to the public, impacting all plugin versions up to 3.19.0. The security update that addressed the problem was version 3.20.0, while the vendor has already released 3.21.0 by now, which is the recommended upgrade target.
The exploitation attempts are still ongoing, so users of the YITH WooCommerce Gift Cards Premium plugin are recommended to upgrade to version 3.21 as soon as possible.
Unfortunately, many sites still use the older, vulnerable version, and hackers have already devised a working exploit to attack them. The exploitation effort is said to be underway, with threat actors leveraging the vulnerability to upload backdoors on the sites, obtain remote code execution, and perform takeover attacks.





