Junglewise Threat Intelligence

CVE-2026-82921: ShopEx ECShop unrestricted file upload in admin pack

CVE-2026-82921 · Severity: high · CVSS 7.3 · Published 2026-08-31

Executive brief

ShopEx ECShop is an e-commerce platform used to build and manage online stores. A flaw in the admin pack functionality allows attackers to upload malicious files by bypassing image type validation, potentially enabling them to execute code on the server and compromise the entire store system.

Technical details

The vulnerability exists in the check_img_type function within admin/pack.php, where the pack_img parameter is not properly validated. This allows an attacker to bypass file type restrictions and upload arbitrary files to the server. The attack is remotely exploitable and requires access to the admin interface or the affected upload endpoint. Successful exploitation enables arbitrary file upload, which could lead to remote code execution depending on server configuration. A patch or update from the vendor is not confirmed to be available at this time.

Affected products

  • ShopEx ECShop up to 2.5.1

Timeline

  • 2026-08-31: disclosed
  • other: Vendor contacted early but did not respond

References

Related threats