File Upload Vulnerability in AF Companion WordPress Plugin
CVE-2026-84738
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-84738?
The AF Companion WordPress plugin is susceptible to a file upload vulnerability that allows users with low-privileged store-management roles to upload arbitrary files. This flaw stems from inadequate validation of file types in one of its import features, potentially enabling the execution of malicious PHP scripts. As a result, attackers can exploit this vulnerability to achieve unauthorized remote code execution, posing a significant security risk to websites utilizing this plugin.
Affected Version(s)
AF Companion 0 < 2.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.