Junglewise Threat Intelligence

CVE-2026-56027: Pluggabl Booster for WooCommerce arbitrary file upload

CVE-2026-56027 · Severity: critical · CVSS 9.9 · Published 2026-06-26

Executive brief

Booster for WooCommerce is a popular WordPress plugin used to add various features and customizations to online stores. A critical security flaw allows users with customer-level accounts to upload malicious files, such as web shells, to the server. This could lead to a complete takeover of the website, theft of customer data, and disruption of business operations.

Technical details

The Booster for WooCommerce plugin for WordPress (versions 8.0.1 and below) contains an unrestricted file upload vulnerability (CWE-434). The flaw allows an authenticated user with 'Customer' privileges to upload files with dangerous extensions to the server. This occurs due to insufficient validation of file types during the upload process. An attacker can exploit this to upload a PHP backdoor or web shell, leading to remote code execution (RCE) and full site compromise. The vulnerability is addressed in version 8.0.2.

Affected products

  • Pluggabl Booster for WooCommerce <= 8.0.1

Timeline

  • 2026-03-02: disclosed: Reported by Jakub Herman
  • 2026-06-23: advisory: Patchstack published advisory
  • 2026-06-26: patched: NVD published date; patch available in 8.0.2

References