Impact
The 3D Product configurator for WooCommerce plugin is vulnerable to remote code execution because the "xpv_image" POST parameter is accepted without authentication or nonce verification and is then echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This lack of sanitization and the presence of a commented-out security check allow an attacker to inject arbitrary PHP code that will be executed on the server as the web‑process user. The flaw can be exploited by any unauthenticated user, granting full control over the affected site’s file system and data.
Affected Systems
The vulnerability exists in the expivi 3D Product configurator for WooCommerce plugin for WordPress in all releases up to and including version 2.16.2. Sites running any of these versions are impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score is not available. The flaw is not yet listed in the CISA KEV catalog. Attackers can trigger the vulnerability with a single unauthenticated POST request to any URL on the site, leading to immediate code execution on the server without requiring prior authentication.
OpenCVE Enrichment