The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the Veeqo for WooCommerce WordPress plugin through 2.2.8 download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.
Title Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T06:00:19.300Z

Reserved: 2026-09-18T09:25:49.846Z

Link: CVE-2026-93550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:29.307

Modified: 2026-10-11T07:17:29.307

Link: CVE-2026-93550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.