CVE-2026-3891
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected products
- Xforwoocommerce, Payrexx Payment Gateway For Woocommerce
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 25.1% (98th percentile)
- Weakness
- CWE-434
- NVD status
- Deferred
- Published
- 2026-03-13
CVE-2026-3891 at NVD
19 known exploits for CVE-2026-3891
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-3891
CVE-2026-3891
CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
CVE-2026-3891
CVE-2026-3891
CVE-2026-3891
CVE-2026-3891-Linux
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
Exploit for CVE-2026-3891
π WordPress Pix for WooCommerce 1.5.0 Shell Upload
Exploit for CVE-2026-3891
Exploit for CVE-2026-3891
Exploit for CVE-2026-3891
Exploit for CVE-2026-3891
Mephisto
Exploit for CVE-2026-3891
Exploit for CVE-2026-3891
Exploit for CVE-2026-3891
WordPress Unauthenticated RCE via Pix for WooCommerce plugin