← Back to browse · API

CVE-2026-3891

Severity
CRITICAL
CVSS
9.8
EPSS
0.08797
Risk score
42.28
CISA KEV
No
PoC
Yes
Published
2026-03-13
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2026-11760
Products
linknacional:Pix for WooCommerce 0 ≤1.5.0
Sources
github d9988c5919ca7024ada42a1d|CVE-2026-3891
packetstorm 289b7ed63ad557bd50934873|CVE-2026-3891
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-3891
packetstorm 5d415646b40fd12c304e14d7|CVE-2026-3891
euvd EUVD-2026-11760

Description

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

References