Arbitrary File Upload Vulnerability in WooCommerce License Manager by Firassaidi
CVE-2026-28114
9.1CRITICAL
What is CVE-2026-28114?
The WooCommerce License Manager plugin by Firassaidi exposes a critical vulnerability that allows unauthorized users to upload files of dangerous types, potentially leading to the deployment of malicious web shells on the server. This vulnerability affects versions of the plugin through 7.0.6, enabling attackers to exploit the unrestricted file upload feature, compromising the security of web servers and user data.
Affected Version(s)
WooCommerce License Manager 0 <= 7.0.6