CVE-2026-3891 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 16, 2026
Pix for WooCommerce - Unrestricted File Upload
Overview
Pix for WooCommerce plugin for WordPress <= 1.5.0 contains an unrestricted file upload vulnerability caused by missing capability check and file type validation in 'lkn_pix_for_woocommerce_c6_save_settings', letting unauthenticated attackers upload arbitrary files, potentially leading to remote code execution.
Severity & Score
Impact
Unauthenticated attackers can upload arbitrary files, potentially leading to remote code execution and full server compromise.
Mitigation
Update to the latest version of Pix for WooCommerce plugin.
References
- https://plugins.trac.wordpress.org/browser/payment-gateway-pix-for-woocommerce/tags/1.4.0/Includes/LknPaymentPixForWoocommercePixC6.php#L694
- https://plugins.trac.wordpress.org/changeset/3480639/payment-gateway-pix-for-woocommerce#file56
- https://www.wordfence.com/threat-intel/vulnerabilities/id/20188fd3-c330-4c76-912b-72731e14c450?source=cve
Social Media Activity(2 posts)
š“ CVE-2026-3891 - Critical (9.8) The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, ... š https://www.thehackerwire.com/vulnerability/CVE-2026-3891/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-3891 - Critical (9.8) The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, ... š https://www.thehackerwire.com/vulnerability/CVE-2026-3891/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2026-3891
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- unrestricted_file_upload
- Status
- unconfirmed
- EPSS
- 12.8%
- Social Posts
- 2
CWE
- CWE-434
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H