Junglewise Threat Intelligence

CVE-2026-84738: AF Companion WordPress plugin arbitrary file upload to RCE

CVE-2026-84738 · Severity: critical · CVSS 9.1 · Published 2026-09-18

Executive brief

The AF Companion WordPress plugin before version 2.2.0 contains a file upload vulnerability in its import feature that does not validate uploaded file types. An attacker with store-manager privileges can upload malicious PHP files to the server, gaining the ability to execute arbitrary code and take over the WordPress installation. This vulnerability allows complete compromise of websites using the affected plugin version.

Technical details

The vulnerability is an arbitrary file upload leading to remote code execution (CWE-94: Improper Control of Generation of Code), located in one of the plugin's import features. The affected component fails to validate file types during upload, allowing an authenticated user with a low-privileged store-manager role to upload arbitrary files, including PHP executables. An attacker can exploit this by uploading a PHP shell and accessing it through the web server, achieving unauthenticated code execution with the web server's privileges. The vulnerability requires store-manager authentication to trigger. The fix is available in version 2.2.0 and later.

Affected products

  • AF Companion AF Companion before 2.2.0

Timeline

  • 2026-09-16: disclosed
  • 2026-09-18: advisory
  • 2026-09-18: patched: Fixed in version 2.2.0

References