CVE-2026-84738: AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with a low-privileged store-management role can exploit the vulnerable import feature. The issue does not require administrator-level WordPress access.
What capability does an attacker gain through successful exploitation?
The attacker can upload arbitrary files, including PHP files, through the affected import feature. Uploading and executing a PHP file can result in remote code execution on the WordPress server.
Which installations are affected?
AF Companion versions before 2.2.0 are affected. The provided information does not establish whether the vulnerable import feature is enabled or reachable in every default configuration.