CVE-2026-84738
AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
| Vendor | unknown |
| Product | af companion |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown af companion
Be the first to know when new unknown vulnerabilities affecting unknown af companion are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / AF Companion
0 < 2.2.0
References
Credits
Farhan Fawwaz Saputra WPScan