CVE-2026-93550
Received Received - Intake

Arbitrary File Write in Veeqo for WooCommerce WordPress Plugin

Vulnerability report for CVE-2026-93550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Veeqo for WooCommerce 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Veeqo for WooCommerce WordPress plugin up to version 2.2.8. It allows users with Subscriber-level access or higher to exploit an arbitrary file upload issue through the plugin's remote bridge-installation process. The plugin does not restrict who can trigger this process or validate the provided URL before downloading and extracting an archive, enabling attackers to upload malicious PHP files into the WordPress root directory.

Detection Guidance

Check if the Veeqo for WooCommerce plugin version 2.2.8 or below is installed. Look for unauthorized PHP files in the WordPress root directory. Review server logs for suspicious download or extraction activities from untrusted URLs.

Impact Analysis

An attacker with Subscriber-level access could upload malicious PHP files to your WordPress site, potentially leading to complete site compromise, data theft, or further attacks against visitors. This could result in unauthorized access, defacement, or malware distribution from your site.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR and HIPAA requirements for data protection and access controls. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Disable the Veeqo for WooCommerce plugin immediately if installed. Monitor for unauthorized file uploads or modifications in the WordPress root directory. Apply any available updates once released. Restrict Subscriber-level access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart