/Vulnerability Library

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

CVE-2026-3891
Verified

Description

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Severity

Critical

CVSS Score

9.8

Exploit Probability

30%

Affected Product

payment_gateway_pix_for_woocommerce

Published Date

July 15, 2026

Template Author

m4sh_wacker

CVE-2026-3891.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-3891
CWE ID:
cwe-434

References

https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploithttps://wordpress.org/plugins/payment-gateway-pix-for-woocommerce/

Remediation Steps

Update to the latest version of Pix for WooCommerce plugin.