๐Ÿ” CVE Alert

CVE-2026-93550

UNKNOWN 0.0

Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.

Vendor unknown
Product veeqo for woocommerce
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown veeqo for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown veeqo for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Veeqo for WooCommerce
0 โ‰ค 2.2.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/09517757-2f99-42d5-8300-e1f618373059/

Credits

Naoki Kawahigashi WPScan