CVE-2026-93550
Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.
| Vendor | unknown |
| Product | veeqo for woocommerce |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown veeqo for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown veeqo for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Veeqo for WooCommerce
0 โค 2.2.8
References
Credits
Naoki Kawahigashi WPScan