WordPress Plugin Vulnerabilities

Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process

Description

The plugin does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the plugin download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-10 (about 8 hours ago)

Other