Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-93550
CVE-2026-93550
Description
The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.2.8
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.