CVE-2026-3891PoC

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • Peaked 6d ago at 5 mentions (2026-03-13); latest day: 2
  • 14 total mentions across 7 days

Deep dive

Activity timeline14 mentions / 7d
01345Mentions · 2026-03-13: 5Mentions · 2026-03-27: 2Mentions · 2026-03-30: 1Mentions · 2026-06-04: 1Mentions · 2026-07-16: 2Mentions · 2026-07-17: 1Mentions · 2026-07-21: 2PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-07-16: 2PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-21: 2Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-06-04: 1Exploit Tool / Code · 2026-07-16: 2Exploit Tool / Code · 2026-07-21: 2Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-13: 5Technical Details · 2026-03-27: 2Technical Details · 2026-03-30: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-21: 103-1303-2703-3006-0407-1607-1707-21
Signal classification4 categories
PoC
642.9%
Disclosure
535.7%
Exploit
214.3%
Patch
17.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-135
Disclosure5
2026-03-272
Patch1PoC1
2026-03-301
PoC1
2026-06-041
PoC1
2026-07-162
PoC2
2026-07-171
PoC1
2026-07-212
Exploit2
Full discourse14 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-3891: A critical Unauthenticated Arbitrary File Upload vulnerability found in the Pix for WooCommerce WordPress plugin in versions up to and including 1.5.0. PoC: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit https://t.co/dAciF2JPPo

    Post summary

    The post announces CVE-2026-3891, describes it as a critical unauthenticated arbitrary file upload flaw in Pix for WooCommerce, and offers a public PoC repository, but makes no claim of active exploitation or availability of a patch.

    14311537218.0K
    234.5K followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    Exploit

    CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit By: @m4sh__wacker Source: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit https://t.co/Uv21zqCZmj

    Post summary

    A GitHub repository has been released containing exploit code for CVE‑2026‑3891 targeting the Pix plugin for WooCommerce.

    1240115365.2K
    56.8K followersView on X
  • Clandestine@akaclandestine
    PoC

    https://github.com/shinthink/CVE-2026-3891

    Post summary

    The provided GitHub link points to a repository that likely contains a proof‑of‑concept exploit for CVE‑2026‑3891, but no evidence of active exploitation, patching, or detailed technical breakdown is presented in the text.

    06022112.9K
    64.1K followersView on X
  • Hack32@Hack32_
    Exploit

    Demonstration of CVE-2026-3891: Arbitrary File Upload leading to RCE in the Pix for WooCommerce plugin. https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit #CVE20263891 #WordPress #WooCommerce #CyberSecurity #Vulnerability #Pentesting https://t.co/AmLpVFEWKu

    Post summary

    The tweet shares a demonstration of CVE-2026-3891, an arbitrary file upload vulnerability causing RCE in the Pix for WooCommerce plugin, and includes a GitHub link to exploit code.

    1002361.4K
    793 followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - Nxploited/CVE-2026-3891: Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload · GitHub https://github.com/Nxploited/CVE-2026-3891?tab=readme-ov-file

    Post summary

    The text points to a GitHub repository for CVE-2026-3891, indicating an unauthenticated arbitrary file upload vulnerability in Pix for WooCommerce versions <=1.5.0. It provides a link that likely contains a PoC but no details on patches, active exploitation, or false positives.

    040981.7K
    61.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-3891 - critical 🚨 Pix for WooCommerce &lt;= 1.5.0 - Unauthenticated Arbitrary File Upload &gt; The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3891 @pdnuclei #NucleiTemplates...

    Post summary

    CVE-2026-3891 exposes an unauthenticated arbitrary file upload flaw in Pix for WooCommerce versions <=1.5.0, with a detection template shared on Project Discovery.

    040123740
    1.3K followersView on X
  • Nxploited@Nxploited
    PoC

    💣 Pix for WooCommerce <= 1.5.0 – Unauthenticated Arbitrary File Upload CVE ID: (Nxploited) – Nxploited ZeroDay Hub PoC:https://github.com/Nxploited/CVE-2026-3891 Channel: https://t.me/KNxploited #CyberSecurity #WordPress #Vulnerability #Exploit #PrivilegeEscalation #Infosec #BugBounty #SecurityResearch

    Post summary

    A Proof‑of‑Concept demonstrating an unauthenticated arbitrary file upload in Pix for WooCommerce (CVE‑2026‑3891) is publicly shared via a GitHub repository; no active exploitation or patch information is reported.

    00014232
    96 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3891: CRITICAL] WordPress Pix for WooCommerce plugin up to version 1.5.0 is at risk due to arbitrary file uploads vulnerability, enabling potential remote code execution by unauthenticated attackers.#cve,CVE-2026-3891,#cybersecurity https://cvefind.com/CVE-2026-3891

    Post summary

    This post highlights a critical arbitrary file upload flaw in WordPress Pix for WooCommerce (v≤1.5.0) that could allow remote code execution, but does not include a PoC, exploit code, or evidence of current exploitation.

    1000071
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3891 - Critical The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_sav... https://www.thehackerwire.com/vulnerability/CVE-2026-3891/ https://t.co/99UGonk3fn

    Post summary

    The tweet announces CVE-2026-3891 as a critical arbitrary file upload vulnerability in the Pix for WooCommerce plugin, providing basic technical details without any references to PoC, exploitation tools, or patches.

    0000145
    135 followersView on X
  • laxlix@laxlix267708
    PoC

    ,🚨 GitHub 监控消息提醒 🚨 发现关键词: #CVE-2026 #Exploit #RCE 📦 项目名称: CVE-2026-3891-Linux 👤 项目作者: willygailo 🛠 开发语言: Python ⭐ Star数量: 1 | 🍴 Fork数量: 0 📅 更新时间: 2026-05-31 09:49:21 📝 项目描述: ⚡ This tool exploits CVE-2026-3891, a critical

    Post summary

    A GitHub project named CVE-2026-3891-Linux offers a Python tool exploiting the critical CVE, acting as a proof‑of‑concept without evidence of active exploitation or a patch.

    0000066
    2 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    WooCommerce Security Alert: CVE-2026-3891 Affects Pix for WooCommerce on #WordPress https://nvd.nist.gov/vuln/detail/CVE-2026-3891 What’s the risk: A missing capability check and missing file-type validation can let unauthenticated attackers upload arbitrary files, which may lead to remote code execution on vulnerable stores. How to protect your site: Update the plugin beyond 1.5.0, review file upload paths and admin settings Scan your WooCommerce store for malicious files or persistence. https://quttera.com/wordpress-malware-scanner #WooCommerce #WordPressSecurity #CVE #WebSecurity #Malware #RCE

    Post summary

    The post announces a RCE flaw in Pix for WooCommerce, details the technical cause, and emphasizes updating the plugin and scanning to mitigate the risk.

    0000048
    37 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3891 The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_fo… https://www.cve.org/CVERecord?id=CVE-2026-3891 ----- Traducción: CVE-2026-3891 El … http://infoflow.cloud`

    Post summary

    The tweet announces a new vulnerability (CVE‑2026‑3891) in the Pix for WooCommerce plugin, detailing the flaw (arbitrary file upload due to missing checks) but does not provide PoC, exploit, patch, or evidence of active exploitation.

    0000034
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3891 The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_fo… https://www.cve.org/CVERecord?id=CVE-2026-3891

    Post summary

    The text announces that the Pix for WooCommerce plugin is vulnerable to arbitrary file uploads because of missing capability and file type checks; no PoC, exploitation evidence, or patch is referenced.

    00000465
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3891: Pix for WooCommerce &lt;= 1.5.0 - Un... Zero-auth file upload with no validation = instant webshell deployment on any WooCommerce site running this payment plug... https://zerodaysignal.com/vulnerability/CVE-2026-3891 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑3891, a zero‑authentication file‑upload flaw in Pix for WooCommerce (≤1.5.0) that permits instant webshell deployment, and provides a link for further details without sharing a PoC or exploit code.

    0000076
    144 followersView on X

Explore more