Detects the Pix for WooCommerce WordPress plugin at version 1.5.0 or earlier, where the lkn_pix_for_woocommerce_c6_save_settings AJAX action accepts arbitrary file uploads without authentication or file type validation. An unauthenticated attacker can obtain a nonce from an exposed endpoint and upload a PHP webshell to a predictable path, achieving remote code execution.
Is your app exploitable through CVE-2026-3891?
Scan your domain free