Description
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution via Unauthenticated Arbitrary File Upload
Action: Immediate Patch
AI Analysis

Impact

The MIPL Grouped Checkout Fields for WooCommerce plugin contains a flaw in the mipl_wc_upload_file function where file type validation is omitted. This omission permits any visitor to upload a file of any type to the site’s server. The uploaded file can contain malicious code, potentially allowing an attacker to execute code on the server, compromise confidentiality, integrity, and availability of the site, and possibly pivot to other systems. The weakness corresponds to CWE-434, File Upload with Dangerous File Types.

Affected Systems

WordPress sites that have the MIPL Grouped Checkout Fields for WooCommerce plugin installed with version 1.2.1 or earlier are impacted. The affected vendor is mulika, and the plugin offers a Configure & Organize Checkout Fields feature.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. Because the vulnerability is exploitable by unauthenticated users through the web interface, an attacker does not need special permissions to upload a file. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, but the lack of mitigation and high severity suggest a high likelihood of exploitation, especially on public-facing sites.

Generated by OpenCVE AI on September 11, 2026 at 06:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MIPL Grouped Checkout Fields for WooCommerce plugin to the latest version (≥ 1.2.2) which removes the missing type validation in mipl_wc_upload_file.
  • If a plugin upgrade is not immediately possible, disable the file upload handler by removing or deactivating the upload action within the plugin, or restrict upload capabilities for all users via role‑based permission settings.
  • Deploy a web application firewall or security plugin that enforces strict file type checks and blocks uploads of disallowed file extensions or MIME types.

Generated by OpenCVE AI on September 11, 2026 at 06:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mulika
Mulika mipl Grouped Checkout Fields For Woocommerce. Customize & Organize Checkout Fields.
Wordpress
Wordpress wordpress
Vendors & Products Mulika
Mulika mipl Grouped Checkout Fields For Woocommerce. Customize & Organize Checkout Fields.
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mulika Mipl Grouped Checkout Fields For Woocommerce. Customize & Organize Checkout Fields.
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:12.419Z

Reserved: 2026-05-17T09:55:22.575Z

Link: CVE-2026-8778

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:18:04.617

Modified: 2026-09-11T21:17:58.797

Link: CVE-2026-8778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type