Critical RCE in AF Companion WordPress Plugin (CVE-2026-84738)
ID: 443a1147-6fc9-58c1-a0e5-4fe03f346cf7
STIX ID: report--443a1147-6fc9-58c1-a0e5-4fe03f346cf7
Feed Name: CosmicBytez Labs
Threat Score
A critical authenticated arbitrary file upload vulnerability (CVE-2026-84738, CVSS 9.1) in the AF Companion WordPress plugin (<=2.1.x) allows users with the low-privileged store-management role to upload PHP files via the import feature, enabling remote code execution, privilege escalation, data exfiltration, and persistence; the report details affected versions, attack steps, detection indicators, and remediation (update to 2.2.0, audit accounts, scan for webshells).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
