Pix for WooCommerce <=1.5.0 Arbitrary File Upload (CVE-2026-3891)
CVE-2026-3891 Published on March 13, 2026

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD

Timeline

Vendor Notified

Disclosed 2 days later.

Weakness Type

What is an Unrestricted File Upload Vulnerability?

The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

CVE-2026-3891 has been classified to as an Unrestricted File Upload vulnerability or weakness.


Affected Versions

linknacional Pix for WooCommerce:

Exploit Probability

EPSS
2.78%
Percentile
84.86%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.