What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.
Explanation of Vulnerability in Simple Terms
02Summary
WooCommerce License Manager versions 7.0.6 and earlier allow authenticated administrators to upload files without proper validation. An attacker with admin access can upload malicious files to compromise the site. The vulnerability affects file handling across the entire WordPress installation due to scope change.
What an attacker can do
03Attacker Capabilities
Upload malicious files to the site and execute code if they have admin access.
Potential impact on your site
04Site Impact
A compromised admin account can upload files that execute code, potentially taking over your entire WordPress site.
Conditions required to exploit
05Prerequisites
Attacker must have WordPress administrator privileges; no user interaction required.
Key dates
06Disclosure timeline
March 5, 2026
CVE published
April 28, 2026
Record updated