SECURITYCRITICALCVE-2026-103889

CVE-2026-103889: Unauthenticated RCE in 3D Product Configurator for WooCommerce

An unauthenticated attacker can POST a malicious xpv_image payload to the WooCommerce 3D Product Configurator plugin for RCE (CVSS 9.8).

Dylan H.

Security Team

October 10, 2026
7 min read
CVE-2026-103889: Unauthenticated RCE in 3D Product Configurator for WooCommerce

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • expivi — 3D Product configurator for WooCommerce ≤ 2.16.2

Overview

3D Product configurator for WooCommerce (WordPress.org slug expivi, maintained by vendor Expivi) lets WooCommerce stores offer an interactive 3D product-customization experience, including rendering customer configurations into PDF quotes/order sheets. CVE-2026-103889 is a critical, unauthenticated remote code execution flaw in the plugin's wp_loaded handler: the handler processes an attacker-supplied xpv_image POST parameter with no sanitization, and the one piece of code that was supposed to gate the request — a nonce and authentication check — is entirely enclosed in a block comment, with nothing left in its place. The endpoint is therefore reachable, unauthenticated, via a single POST request to any URL on the site. NVD published the record on 2026-10-10 with a CVSS 3.1 score of 9.8 (Critical); the finding was reported through Wordfence's bug-bounty program and credited to researcher Osman Hussein.


Technical Details

FieldValue
CVE IDCVE-2026-103889
CVSS Score9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-434 (Unrestricted Upload of File with Dangerous Type) — the missing gate is also describable as CWE-862 (Missing Authorization) / CWE-352 (CSRF, nonce bypass)
Attack VectorNetwork — a single unauthenticated HTTP POST
Privileges RequiredNone
User InteractionNone
Affected Componentwp_loaded request handler, xpv_image parameter (plugin SVN: classes/woocommerce/class-expivi-cart-manager.php, classes/pdf/class-pdf.php)
Affected Versions3D Product configurator for WooCommerce ≤ 2.16.2
Fixed InNot independently confirmed at time of writing — see Mitigation
Vendor / Plugin SlugExpivi / expivi (WordPress.org, ~200 active installs)
Discovered ByOsman Hussein, via Wordfence's bug-bounty program (Wordfence Threat Intelligence advisory 46f69f7b-6d9b-494d-b123-63fc5ebcb6f3)

How It Works

The plugin hooks request handling into WordPress's wp_loaded action and reads an xpv_image value straight from $_POST. That value is meant to represent an image for the 3D configurator/PDF-quote feature, and it is fed — unescaped and unsanitized — into an HTML template that the plugin renders to PDF using Dompdf, with PHP execution enabled in that rendering context.

The handler's source does contain a nonce-and-authentication check — but a code review found that the check is wrapped entirely inside a /* ... */ block comment, with no active replacement left behind. In other words, the gate exists in the source tree but never executes. Because wp_loaded fires on effectively every WordPress request and the handler performs no capability check of its own, any unauthenticated visitor can POST to any URL on the site and reach the vulnerable code path directly.

Combined with Dompdf's PHP execution being enabled for the generated template, an attacker who controls the xpv_image value controls content that ends up being rendered — and executed — server-side, giving them remote code execution with no account, no nonce, and no prior interaction with the site.


Impact Assessment

Impact AreaDescription
ConfidentialityHigh — RCE gives an attacker full read access to site files, database credentials, and any other secrets on the host
IntegrityHigh — an attacker can modify site content, plant webshells, or pivot into the broader WooCommerce store/order data
AvailabilityHigh — arbitrary code execution can be used to disrupt or take down the site entirely
Authentication RequiredNone
User InteractionNone

Who Is At Risk

  • Any WooCommerce store running 3D Product configurator for WooCommerce (expivi) ≤ 2.16.2
  • Sites that expose the plugin's handler to the public internet (the default for a customer-facing WooCommerce store) — there is no network segmentation that mitigates this short of blocking the endpoint entirely
  • Given the plugin's relatively low install base (~200 active installs per its WordPress.org listing), the blast radius is smaller than for a flagship plugin, but severity for an affected site is still maximal — full unauthenticated RCE

Attack Chain

  1. Identify the target — Attacker fingerprints a WooCommerce site running the vulnerable plugin (plugin enumeration, asset paths, or known endpoint probing).
  2. Craft the request — Attacker builds a single HTTP POST request to any URL on the target site, setting the xpv_image parameter to a malicious payload.
  3. Bypass the (non-existent) gate — The wp_loaded handler processes the request; the commented-out nonce/auth check never runs, so there is no authentication barrier to cross.
  4. Trigger rendering — The unsanitized xpv_image value is embedded into an HTML template and passed to Dompdf for PDF rendering with PHP execution enabled.
  5. Achieve RCE — The attacker's payload executes server-side during rendering, giving them code execution in the context of the web server.
  6. Post-exploitation — From there, the attacker can plant a persistent webshell, exfiltrate the WordPress/WooCommerce database, or use the compromised host as a pivot point.

Mitigation

Immediate Actions

  • A patched version has not been independently confirmed as of this writing. Public advisories (Wordfence, Patchstack) recommend site owners update beyond 2.16.2 as soon as a fixed release is available — check the plugin's WordPress.org changelog before assuming a fix is live.
  • Until a confirmed fix is available, disable or remove the 3D Product configurator for WooCommerce plugin. Given the unauthenticated, zero-interaction nature of this flaw, this is the only mitigation that fully closes the exposure.
  • If the plugin cannot be removed immediately, block POST requests carrying an xpv_image parameter at the WAF/reverse-proxy layer as a stopgap — this is a mitigation, not a fix, and should not replace removal or patching.

Detection Opportunities

  • Review web server access logs for POST requests containing xpv_image from unfamiliar or unauthenticated clients, especially to unexpected URLs (the handler fires on wp_loaded, so it can be reached via virtually any site path).
  • Check for unexpected PHP files, modified theme/plugin files, or new admin accounts created around the time of any suspicious xpv_image POST activity.
  • Monitor outbound connections and process execution from the web server user for signs of a planted webshell or reverse shell.

Defence-in-Depth

  • Run WooCommerce plugin inventories regularly and prioritize patching or removing low-install, infrequently maintained plugins — this plugin's only prior CVE (CVE-2022-1953, Arbitrary File Deletion) suggests a pattern of weaker security review.
  • Disable PHP execution within any Dompdf (or similar HTML-to-PDF) rendering sandbox used by third-party plugins, independent of this specific flaw.
  • Apply the principle of least exposure: where a plugin's functionality doesn't need to be reachable by anonymous visitors, front it with authentication at the web server or WAF layer rather than relying solely on the plugin's own checks.

Background

3D Product configurator for WooCommerce is a niche WooCommerce add-on from vendor Expivi that lets shoppers visually customize products in 3D before checkout, with the configured result rendered into a PDF quote or order document. That PDF-rendering path — built on Dompdf — is also where this vulnerability lives: a single commented-out security check turned a routine image-parameter handler into a direct, unauthenticated route to server-side code execution. The plugin's only previous CVE (CVE-2022-1953, Arbitrary File Deletion, CVSS 5.4) was lower severity, but the pattern — insufficient input handling in a WooCommerce-adjacent plugin — is a recurring theme in the WordPress plugin ecosystem. Low install counts don't equal low risk: any site running an affected version is fully exposed regardless of the plugin's overall popularity.


References