All verified exploits

CVE-2026-3891 Pix for WooCommerce Unauthenticated File Upload

Deterministic critical WordPress Added cve-verified-cve-2026-3891

Detects the Pix for WooCommerce WordPress plugin at version 1.5.0 or earlier, where the lkn_pix_for_woocommerce_c6_save_settings AJAX action accepts arbitrary file uploads without authentication or file type validation. An unauthenticated attacker can obtain a nonce from an exposed endpoint and upload a PHP webshell to a predictable path, achieving remote code execution.

Related WordPress exploits

Is your app exploitable through CVE-2026-3891?

Scan your domain free