VYPR

Pix for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-3891CriMar 13, 2026
    risk 0.60cvss 9.8epss 0.09

    The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible…