Description
This Metasploit module exploits an Unauthenticated Arbitrary File Upload vulnerability in the Pix for WooCommerce plugin for WordPress.
Attackers can leverage the missing capability check and insufficient file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function to upload arbitrary files to the affected server, which may lead to remote code execution under the web server's privileges.
The affected versions include all releases up to and including 1.5.0.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/wp/plugin_pix_unauth_rce_cve_2026_3891msf undefined(plugin_pix_unauth_rce_cve_2026_3891) > show actions ...actions...msf undefined(plugin_pix_unauth_rce_cve_2026_3891) > set ACTION < action-name >msf undefined(plugin_pix_unauth_rce_cve_2026_3891) > show options ...show and set options...msf undefined(plugin_pix_unauth_rce_cve_2026_3891) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub