๐Ÿ” CVE Alert

CVE-2026-84738

UNKNOWN 0.0

AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.

Vendor unknown
Product af companion
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown af companion

Be the first to know when new unknown vulnerabilities affecting unknown af companion are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / AF Companion
0 < 2.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1d6c7f60-570e-4729-a2d5-463e0b62942e/

Credits

Farhan Fawwaz Saputra WPScan