Sceawere

Vulnerability Detail

CVE-2026-93550UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Remote Code Execution

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
8h ago
Vendor
Unknown
Product
Veeqo for WooCommerce
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T07:17:29.307Z",
  "pubdate": "2026-10-11T07:17:29.307Z",
  "executiveSummary": "The Veeqo for WooCommerce plugin through version 2.2.8 contains a critical vulnerability regarding its remote bridge-installation process. The vulnerability stems from insufficient access control and a complete lack of input validation during the archive download and extraction phase.\nThe flaw allows an attacker, authenticated as a WordPress Subscriber or higher, to trigger the installation process using an arbitrary, attacker-controlled URL. This enables the arbitrary download and extraction of malicious archives directly into the WordPress root directory.\nAs the system fails to validate the source or contents of the provided archive, an attacker can deploy arbitrary PHP files, leading to Remote Code Execution (RCE). This compromise grants the attacker full control over the WordPress application and the underlying server environment, potentially leading to unauthorized data access, persistence, and total system compromise. Given the ease of exploitation—requiring only minimal privileges—this vulnerability represents a significant risk to the security and integrity of affected WordPress installations.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper implementation of the plugin's remote bridge-installation functionality. The administrative action intended for plugin setup lacks both authorization checks and server-side validation of the target URL parameter. Specifically, the component responsible for processing the installation request fails to verify the requestor's authorization level beyond a basic check that allows access to Subscribers, and it does not validate that the provided URL points to an authentic or expected resource.\nThe attack flow proceeds as follows: First, an attacker with a low-privileged WordPress account (Subscriber) interacts with the vulnerable installation endpoint. By crafting a malicious request, the attacker specifies a URL pointing to an external server hosting a weaponized archive file. Because the application logic does not perform any sanitization or validation on this URL, it initiates an internal file transfer request.\nUpon receiving the malicious archive, the plugin proceeds to extract the contents directly into the WordPress root directory. Because the system performs no integrity checks or path validation, the attacker can leverage directory traversal sequences or simply supply a ZIP archive containing arbitrary PHP payloads. Once extracted, these PHP scripts become accessible via the web server.\nPost-exploitation, the attacker can execute the newly planted PHP files by directly requesting them through the web browser. This results in the execution of arbitrary commands with the privileges of the web server user. The impact is severe, as it bypasses standard WordPress security constraints, facilitating the installation of web shells, unauthorized database queries, sensitive information exfiltration, and lateral movement within the network environment.\nThis vulnerability affects Veeqo for WooCommerce versions up to and including 2.2.8. The lack of strict origin verification, combined with the insecure handling of server-side file operations, makes this a high-severity Remote Code Execution vector that necessitates immediate remediation."
}
CVE-2026-93550: Unauthenticated Remote Code Execution (MEDIUM Severity, CVSS: 4.3) | Sceawere