0-Day RCE Exploit for an OpenCart Plugin for Sale

Dark Web2026-08-07, 10:10
0-Day RCE Exploit for an OpenCart Plugin for Sale
For informational purposes only.
Vulnerability type: Arbitrary File Upload / Arbitrary File Delete → RCE
Price: Auction (starting bid — $3,000, minimum increment — $1,000, buyout — $10,000)
The author claims to be selling an exploit for an OpenCart plugin that allows arbitrary file upload and deletion on the server without any stated restrictions. According to the seller, a single POST request is enough to obtain a shell, meaning the vulnerability could potentially be used to achieve remote code execution on the e-commerce server.
As proof, the author provides a demonstration showing a file being uploaded to a test server and then accessed through the web interface.
The seller also states that the extension has around 19,000 installs from the official OpenCart Marketplace, representing a significant user base for a single plugin.
OpenCart — a popular open-source CMS for online stores, especially in the small and medium e-commerce segment. According to BuiltWith, there are about 190 thousand active sites on OpenCart worldwide and more than 922 thousand sites that have used the platform historically.
Vendors
Opencart
Products
Opencart
Opencart Marketplace
Opencart Plugin