xShop version 3.0.3, an open-source e-commerce platform built on Laravel, contains an Unrestricted File Upload vulnerability tracked as CVE-2026-49849. An authenticated administrator can exploit this flaw by uploading executable files such as PHP scripts. Once uploaded, a specially crafted PHP file can be executed on the server, achieving Remote Code Execution (RCE). This can lead to full system compromise of the affected server. The vulnerability requires administrator-level authentication to exploit. The issue has been patched in xShop version 3.0.4. A security advisory, pull request, and commit addressing the fix have been published on the project's GitHub repository. Users are strongly advised to upgrade to version 3.0.4 immediately.