Junglewise Threat Intelligence

CVE-2026-42748: WPify WPify Woo Czech unrestricted file upload

CVE-2026-42748 · Severity: critical · CVSS 9.9 · Published 2026-05-27

Executive brief

WPify Woo Czech, a WordPress plugin used to adapt WooCommerce for the Czech market, contains a critical security flaw that allows users with low-level account access to upload malicious files. An attacker could use this to install a 'web shell,' effectively taking full control of the website's server. This could lead to the theft of customer data, complete site defacement, or the use of the server for further attacks.

Technical details

The WPify Woo Czech (wpify-woo) plugin for WordPress is vulnerable to an unrestricted file upload (CWE-434) in versions up to and including 5.4.1. The flaw allows an authenticated attacker with basic user permissions to upload files with dangerous extensions, such as .php, to the web server. By uploading a web shell, the attacker can achieve remote code execution (RCE) with the privileges of the web server process. The vulnerability has a CVSS score of 9.9 due to the potential for a complete scope jump and total compromise of confidentiality, integrity, and availability. Users are advised to update to a version higher than 5.4.1 if available.

Affected products

  • WPify WPify Woo Czech (wpify-woo) <= 5.4.1

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References