PT-2026-20630 · WordPress · Prodigy Commerce+1

Athiwat Tiprasaharn

+2

·

Published

2026-02-19

·

Updated

2026-03-17

·

CVE-2026-0926

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prodigy Commerce versions prior to 3.2.9
Description The Prodigy Commerce plugin for WordPress is susceptible to a Local File Inclusion issue. This allows unauthenticated attackers to include and read arbitrary files or execute arbitrary files on the server. Exploitation of this issue can lead to bypassing access controls, obtaining sensitive data, or achieving code execution. The vulnerability is due to insufficient input validation of the parameters[template name] parameter. This allows attackers to include and execute PHP code within uploaded files.
Recommendations Versions prior to 3.2.9 should be updated. As a temporary workaround, consider disabling the Prodigy Commerce plugin until a fix is available. Monitor file uploads for potentially malicious content.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0926

Affected Products

Prodigy Commerce
Wordpress