WordPress Plugin Vulnerabilities
Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process
Description
The plugin does not restrict who can trigger its remote bridge-installation process or validate the URL it is given before downloading and extracting it, allowing users with Subscriber-level access and above to make the plugin download and extract an attacker-controlled archive containing arbitrary PHP files into the WordPress root.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-10 (about 8 hours ago)