File Upload Vulnerability in WooCommerce WordPress Plugin
CVE-2026-19089
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 August 2026
Badges
What is CVE-2026-19089?
The WooCommerce WordPress plugin prior to version 2.0.2 is susceptible to a file upload vulnerability due to its failure to validate the types of files that can be uploaded when its accepted-types setting is left empty. This lack of validation opens the door for unauthenticated attackers to upload arbitrary files. If successful, this can lead to remote code execution on vulnerable servers, particularly those that do not enforce strict directory access rules. Site administrators are urged to update to the latest version to mitigate this risk.
Affected Version(s)
Product Input Fields for WooCommerce 2.0.0 < 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.