The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
PoC: CVE-2026-3891-Linux
⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions ≤ 1.5.0).
PoC: CVE-2026-3891
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC
[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-3891
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
[POC] GHSA-8qqm-fp2q-v734 — CVE-2026-3891
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
[POC] GHSA-8qqm-fp2q-v734 — CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
PoC: CVE-2026-3891
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.
PoC: Mass-Scanner-CVE-2026-3891
CVE-2026-3891 Mass Scanning
PoC: CVE-2026-3891
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
PoC: CVE-2026-3891
Demonstrate an unauthenticated arbitrary file upload exploit in Pix for WooCommerce plugin versions up to 1.5.0 using exposed AJAX endpoints.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free