Unrated severityNVD Advisory· Published Sep 18, 2026
CVE-2026-84738
CVE-2026-84738
Description
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.2.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.