Description
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthenticated attackers to execute code on the server. The only nonce and authentication check in the handler is entirely enclosed in a block comment with no replacement, making the endpoint reachable via a single unauthenticated POST to any URL on the site.
Published: 2026-10-10
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The 3D Product configurator for WooCommerce plugin is vulnerable to remote code execution because the "xpv_image" POST parameter is accepted without authentication or nonce verification and is then echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This lack of sanitization and the presence of a commented-out security check allow an attacker to inject arbitrary PHP code that will be executed on the server as the web‑process user. The flaw can be exploited by any unauthenticated user, granting full control over the affected site’s file system and data.

Affected Systems

The vulnerability exists in the expivi 3D Product configurator for WooCommerce plugin for WordPress in all releases up to and including version 2.16.2. Sites running any of these versions are impacted.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and the EPSS score is not available. The flaw is not yet listed in the CISA KEV catalog. Attackers can trigger the vulnerability with a single unauthenticated POST request to any URL on the site, leading to immediate code execution on the server without requiring prior authentication.

Generated by OpenCVE AI on October 10, 2026 at 05:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the expivi plugin to a version newer than 2.16.2, if available, or remove the plugin entirely.
  • If an update is unavailable, temporarily block all POST requests containing the "xpv_image" parameter using a web‑application firewall or server‑side rule to prevent unauthenticated access.
  • Verify that the site’s configuration disables PHP execution within the Dompdf template rendering path and enforce proper input validation for the "xpv_image" parameter through custom code or a security plugin.

Generated by OpenCVE AI on October 10, 2026 at 05:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthenticated attackers to execute code on the server. The only nonce and authentication check in the handler is entirely enclosed in a block comment with no replacement, making the endpoint reachable via a single unauthenticated POST to any URL on the site.
Title 3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'xpv_image' Parameter
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T04:26:43.225Z

Reserved: 2026-10-01T13:26:55.796Z

Link: CVE-2026-103889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T05:16:39.130

Modified: 2026-10-10T05:16:39.130

Link: CVE-2026-103889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T05:30:09Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type