Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-56027: Booster for WooCommerce <= 8.0.1 allows customers to upload arbitrary files

CVE-2026-56027
Summary

The Booster for WooCommerce plugin allows customers to upload files without proper validation, which means they can potentially upload malicious files. This could lead to security risks and compromise the store's integrity. Update to the latest version of the plugin to fix this issue.

Original title
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Original description
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
nvd CVSS3.1 9.9
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 26 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026