{"id":"CVE-2026-84738","title":"The AF Companion  WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, le…","summary":"The AF Companion  WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, le…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-94"],"product":"AF Companion","affected":["af_companion < 2.2.0"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:08:32.830","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84738","references":[{"url":"https://wpscan.com/vulnerability/1d6c7f60-570e-4729-a2d5-463e0b62942e/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00564,"epssPercentile":0.4539,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T11:07:59.834519Z"},"ingestedAt":"2026-09-18T06:36:37.980Z","slug":"CVE-2026-84738","body":"## Overview\n\nThe AF Companion  WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206727,"id":"CVE-2026-84738","ts":1789731638818,"field":"cvss","old":null,"new":"9.1"},{"seq":206726,"id":"CVE-2026-84738","ts":1789731638818,"field":"severity","old":"none","new":"critical"}]}