# FoxyShop <= 4.9.7 - Missing Authorization to Unauthenticated Limited File Upload

- **ID:** WPSEC-2026-0666
- **Plugin:** FoxyShop (`foxyshop`), https://wordpress.org/plugins/foxyshop/
- **Affected versions:** all versions before 4.9.8
- **Fixed in:** 4.9.8 (Update to 4.9.8 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/foxyshop
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0666/

## Description

The FoxyShop plugin for WordPress is vulnerable to unauthorized file uploads in all versions up to, and including, 4.9.7 due to a missing capability check on the product image upload branch of the plugin's upload endpoint. This makes it possible for unauthenticated attackers who know the endpoint's URL key to upload files of the allowed image and document types to the media library and attach them to any product.

## References

- https://wpsec.com/vuln/WPSEC-2026-0666/
- https://plugins.svn.wordpress.org/foxyshop/tags/4.9.8/
- https://wordpress.org/plugins/foxyshop/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0666/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
