


Perceptive Security
SOC/SIEM Consultancy

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WP…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 15:06:57
Source:
nvd.nist.gov
Web Technologies
CVE-2026-42748 is an unrestricted file upload vulnerability in the WPify Woo Czech WordPress plugin (wpify-woo) that allows attackers to upload web shells to web servers. The vulnerability affects all versions from unknown starting point through version 5.4.1 and earlier. This type of vulnerability enables attackers to gain unauthorized access and execute arbitrary code on the target server by uploading malicious files. The issue has been assigned a high criticality rating due to the potential for complete server compromise. Organizations using the affected plugin versions should update immediately or implement file upload restrictions as a temporary mitigation.
Technical details
Mitigation steps:
Affected products:
WPify Woo Czech
wpify-woo
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42748
https://patchstack.com/database/Wordpress/Plugin/wpify-woo/vulnerability/wordpress-wpify-woo-czech-plugin-5-4-1-arbitrary-file-upload-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
