CVE-2026-103889
Received Received - Intake

Remote Code Execution in 3D Product Configurator for WooCommerce

Vulnerability report for CVE-2026-103889, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthenticated attackers to execute code on the server. The only nonce and authentication check in the handler is entirely enclosed in a block comment with no replacement, making the endpoint reachable via a single unauthenticated POST to any URL on the site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
expivi 3D Product configurator for WooCommerce 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Remote Code Execution flaw in the 3D Product configurator for WooCommerce WordPress plugin. It allows unauthenticated attackers to execute arbitrary code on the server by sending a specially crafted POST request with the 'xpv_image' parameter. The issue occurs due to missing authentication checks, nonce validation, and lack of input sanitization before the parameter is used in a template that allows PHP execution.

Detection Guidance

Check for unauthorized POST requests to any URL on your WordPress site, particularly those targeting the 'xpv_image' parameter. Inspect server logs for suspicious activity or unexpected PHP execution in rendered HTML templates.

Impact Analysis

If exploited, this vulnerability could allow attackers to take full control of your WordPress site, steal sensitive data, install malware, or use your server for malicious activities. Since it requires no authentication, any unauthenticated user can potentially compromise your site.

Compliance Impact

This vulnerability could lead to data breaches, exposing personal or sensitive information. Such breaches may violate GDPR, HIPAA, or other regulations, resulting in legal penalties, fines, or reputational damage. Compliance requires protecting systems from unauthorized access.

Mitigation Strategies

Immediately update the 3D Product configurator for WooCommerce plugin to the latest version beyond 2.16.2. If an update is unavailable, consider disabling the plugin temporarily until a patch is released. Review server logs for signs of exploitation and remove any unauthorized files or scripts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103889. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart