HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

WooCommerce 1.5.0 Plugin Allows Unauthenticated Arbitrary File Upload (CVE‑2026‑3891)

A remote attacker can upload a PHP web‑shell to sites running WooCommerce 1.5.0’s Payment Gateway Pix plugin without authentication, achieving full server‑side code execution. This highlights the need for robust vendor‑risk controls and SOC 2‑aligned evidence of remediation.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 exploit-db.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
exploit-db.com

WooCommerce 1.5.0 – Unauthenticated Arbitrary File Upload (CVE‑2026‑3891)

What Happened – A remote attacker can upload a PHP web‑shell to any site running the WooCommerce 1.5.0 “Payment Gateway Pix for WooCommerce” plugin without authentication. The exploit obtains a nonce via an AJAX call, then abuses the lkn_pix_for_woocommerce_c6_save_settings action to write an arbitrary file under the plugin’s certs_c6 directory, yielding full server‑side code execution.

Why It Matters for Compliance & Audit Readiness

  • The flaw bypasses SOC 2 CC6 – Logical Access Controls by allowing unauthenticated code execution, a scenario continuous‑compliance programs must detect and evidence remediation for.
  • Demonstrating that you have vendor‑risk controls (third‑party plugin vetting, version‑pinning, and continuous monitoring) provides audit‑ready proof that you mitigate supply‑chain exposures.
  • Mapping this vulnerability to a control‑gap and collecting evidence of remediation satisfies the “defensible audit trail” requirement of SOC 2 CC7 – System Operations.

Who Is Affected – E‑commerce retailers, digital marketplaces, and any organization that runs WordPress/WooCommerce with the vulnerable plugin (primarily the Retail/E‑commerce sector).

Recommended Actions

  • Immediately upgrade the plugin to a version > 1.5.0 or remove it if not needed.
  • Apply a Web Application Firewall rule that blocks the admin‑ajax.php actions lkn_pix_for_woocommerce_generate_nonce and lkn_pix_for_woocommerce_c6_save_settings until patched.
  • Record the patch‑management activity in your SOC 2 control evidence repository and map it to CC6/CC7.
  • Add the plugin to your vendor‑risk inventory and enable continuous version‑monitoring alerts.

Source: Exploit‑DB #52642

Technical Notes – The exploit leverages an unauthenticated AJAX endpoint to retrieve a nonce, then uploads a malicious PHP file (woocommerce.php) that executes commands via system($_REQUEST["cmd"]). No CVSS score is published yet, but the remote code execution potential places it in the High severity band. Source: same as above

📰 Original Source
https://www.exploit-db.com/exploits/52642

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →