CVE-2026-28114: Firassaidi Woocommerce License Manager
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.
Affected products
- Firassaidi Woocommerce License Manager: up to and including 7.0.6
Published 2026-03-05. Last modified 2026-06-17.