Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891
Verified
Description
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Severity
Critical
CVSS Score
9.8
Exploit Probability
30%
Affected Product
payment_gateway_pix_for_woocommerce
Published Date
July 15, 2026
Template Author
m4sh_wacker
CVE-2026-3891.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-3891
CWE ID:
cwe-434
Remediation Steps
Update to the latest version of Pix for WooCommerce plugin.