high · CVSS v3 8.8
CVE-2026-84738
The AF Companion WordPress plugin prior to version 2.2.0 lacks proper file type validation in an import feature. This oversight enables low-
Overview
The AF Companion WordPress plugin prior to version 2.2.0 lacks proper file type validation in an import feature. This oversight enables low-privileged store-management users to upload arbitrary files, potentially resulting in remote code execution on the underlying server.
Description
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
Impact
The vulnerability primarily impacts the integrity and availability of the hosting server, along with the confidentiality of stored data. Successful exploitation allows authenticated users with store-management privileges to execute arbitrary code. This can lead to full system compromise from an authenticated perspective.
Remediation
Update the AF Companion WordPress plugin to version 2.2.0 or later where file type validation is properly enforced. Implement strict file upload restrictions and limit the assignment of store-management roles to trusted accounts only. Conduct regular security audits of user roles and installed plugins.
Risk context
Rated as a high severity issue with a CVSS v3 score of 8.8, posing a significant risk due to the potential for remote code execution. Defenders should prioritize immediate patching of the affected plugin to mitigate unauthorized access and system compromise.
Affected products
- AF Companion WordPress plugin
Scores
- Severity
- high
- CVSS v2
- 6.5
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —