Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
Title source: llmExploitation Summary
EIP tracks 10 public exploits for CVE-2026-3891. PoCs published by willygailo, joshuavanderpoll, VeronnX666. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3891, targeting an unauthenticated arbitrary file upload vulnerability in Pix for WooCommerce <= 1.5.0. The exploit is obfuscated using PyArmor and includes a GUI for ease of use.
Description
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Exploits (10)
This repository contains a functional exploit for CVE-2026-3891, targeting an unauthenticated arbitrary file upload vulnerability in Pix for WooCommerce <= 1.5.0. The exploit is obfuscated using PyArmor and includes a GUI for ease of use.
This repository contains a functional exploit for CVE-2026-3891, an unauthenticated arbitrary file upload vulnerability in the Pix for WooCommerce plugin (versions <= 1.5.0). The exploit uploads a PHP webshell to the target server and allows command execution.
This PoC exploits an arbitrary file upload vulnerability in the LKN Pix for WooCommerce WordPress plugin (CVE-2026-3891) via a misconfigured admin-ajax.php endpoint. It uploads a PHP webshell by abusing a nonce generation flaw in the plugin's settings update mechanism.
This repository contains a functional Python exploit for CVE-2026-3891, an unauthenticated arbitrary file upload vulnerability in Pix for WooCommerce <= 1.5.0. The exploit leverages a nonce leak and missing file validation in the `certificate_crt_path` parameter to upload a PHP webshell, achieving remote code execution (RCE).
This exploit targets CVE-2026-3891, an unauthenticated arbitrary file upload vulnerability in the Pix for WooCommerce WordPress plugin (versions ≤1.5.0). The PoC automates nonce retrieval and uploads a malicious PHP file to a web-accessible directory, enabling remote code execution via a simple HTTP request.
This repository contains a Python-based mass scanner for CVE-2026-3891, which checks for a vulnerable WordPress AJAX endpoint (`lkn_pix_for_woocommerce_generate_nonce`) that leaks a nonce value. The tool validates the presence of the vulnerability by sending crafted POST requests and parsing JSON responses, but does not exploit it for code execution or privilege escalation.
The repository provides a functional exploit for CVE-2026-3891, demonstrating an unauthenticated arbitrary file upload vulnerability in Pix for WooCommerce ≤ 1.5.0. It includes detailed steps to generate a nonce, upload a malicious PHP file disguised as a certificate, and achieve remote code execution.
This repository contains a Python-based scanner for CVE-2026-3891, which targets a WordPress AJAX behavior. The tool checks for the presence of a nonce generation endpoint and validates responses, but does not include exploit code for weaponization.
This repository contains a functional exploit for CVE-2026-3891, targeting a file upload vulnerability in the 'lkn_pix_for_woocommerce' WordPress plugin. The exploit automates the process of generating a nonce and uploading a malicious shell via the plugin's settings functionality.
This repository contains a functional Python exploit for CVE-2026-3891, an unauthenticated arbitrary file upload vulnerability in the Pix for WooCommerce plugin (version <= 1.5.0). The exploit uploads a PHP webshell by leveraging a nonce generation endpoint and a file upload endpoint, then allows command execution via the uploaded shell.
Nuclei Templates (1)
http.html:"/wp-content/plugins/payment-gateway-pix-for-woocommerce"
body="/wp-content/plugins/payment-gateway-pix-for-woocommerce"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H