← Back to CVE List
CVE-2026-84738NVD
Description
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| Unknown AF Companion | 0 - < 2.2.0 | N/A |