CRITICAL 9.1 CVE-2026-84738 Published 18 Sept 2026

WordPress AF Companion Plugin Arbitrary File Upload

Worried this affects your website?

The AF Companion WordPress plugin, versions prior to 2.2.0, has a vulnerability in its import feature. It does not validate the type of files uploaded, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones.

This can lead to Remote Code Execution, a serious security risk.

Reference: CVE-2026-84738 on NVD

← Back to Security News