Impact
The AF Companion WordPress plugin allows a low‑privileged store‑manager to import files without checking the MIME type or extension. This flaw lets an attacker upload a PHP file that the web server executes, giving full remote code execution on the host. The vulnerability is a classic code‑injection weakness (CWE‑94) and can compromise file integrity, confidentiality, and availability.
Affected Systems
All WordPress sites using AF Companion version earlier than 2.2.0 are affected. The plugin is identified as Unknown:AF Companion in CNA listings. Any site that has the import feature enabled and grants store‑manager roles is at risk.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity. The EPSS score is less than 1%, suggesting exploitation is unlikely but it remains a serious risk because the flaw enables RCE directly. The vulnerability is not listed in the CISA KEV catalog, but its impact warrants immediate attention. An attacker requires authenticated access with a store‑manager+ role to upload a malicious file, after which the server will execute the code.
OpenCVE Enrichment