Overview
3D Product configurator for WooCommerce (WordPress.org slug expivi, maintained by vendor Expivi) lets WooCommerce stores offer an interactive 3D product-customization experience, including rendering customer configurations into PDF quotes/order sheets. CVE-2026-103889 is a critical, unauthenticated remote code execution flaw in the plugin's wp_loaded handler: the handler processes an attacker-supplied xpv_image POST parameter with no sanitization, and the one piece of code that was supposed to gate the request — a nonce and authentication check — is entirely enclosed in a block comment, with nothing left in its place. The endpoint is therefore reachable, unauthenticated, via a single POST request to any URL on the site. NVD published the record on 2026-10-10 with a CVSS 3.1 score of 9.8 (Critical); the finding was reported through Wordfence's bug-bounty program and credited to researcher Osman Hussein.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-103889 |
| CVSS Score | 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-434 (Unrestricted Upload of File with Dangerous Type) — the missing gate is also describable as CWE-862 (Missing Authorization) / CWE-352 (CSRF, nonce bypass) |
| Attack Vector | Network — a single unauthenticated HTTP POST |
| Privileges Required | None |
| User Interaction | None |
| Affected Component | wp_loaded request handler, xpv_image parameter (plugin SVN: classes/woocommerce/class-expivi-cart-manager.php, classes/pdf/class-pdf.php) |
| Affected Versions | 3D Product configurator for WooCommerce ≤ 2.16.2 |
| Fixed In | Not independently confirmed at time of writing — see Mitigation |
| Vendor / Plugin Slug | Expivi / expivi (WordPress.org, ~200 active installs) |
| Discovered By | Osman Hussein, via Wordfence's bug-bounty program (Wordfence Threat Intelligence advisory 46f69f7b-6d9b-494d-b123-63fc5ebcb6f3) |
How It Works
The plugin hooks request handling into WordPress's wp_loaded action and reads an xpv_image value straight from $_POST. That value is meant to represent an image for the 3D configurator/PDF-quote feature, and it is fed — unescaped and unsanitized — into an HTML template that the plugin renders to PDF using Dompdf, with PHP execution enabled in that rendering context.
The handler's source does contain a nonce-and-authentication check — but a code review found that the check is wrapped entirely inside a /* ... */ block comment, with no active replacement left behind. In other words, the gate exists in the source tree but never executes. Because wp_loaded fires on effectively every WordPress request and the handler performs no capability check of its own, any unauthenticated visitor can POST to any URL on the site and reach the vulnerable code path directly.
Combined with Dompdf's PHP execution being enabled for the generated template, an attacker who controls the xpv_image value controls content that ends up being rendered — and executed — server-side, giving them remote code execution with no account, no nonce, and no prior interaction with the site.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | High — RCE gives an attacker full read access to site files, database credentials, and any other secrets on the host |
| Integrity | High — an attacker can modify site content, plant webshells, or pivot into the broader WooCommerce store/order data |
| Availability | High — arbitrary code execution can be used to disrupt or take down the site entirely |
| Authentication Required | None |
| User Interaction | None |
Who Is At Risk
- Any WooCommerce store running 3D Product configurator for WooCommerce (expivi) ≤ 2.16.2
- Sites that expose the plugin's handler to the public internet (the default for a customer-facing WooCommerce store) — there is no network segmentation that mitigates this short of blocking the endpoint entirely
- Given the plugin's relatively low install base (~200 active installs per its WordPress.org listing), the blast radius is smaller than for a flagship plugin, but severity for an affected site is still maximal — full unauthenticated RCE
Attack Chain
- Identify the target — Attacker fingerprints a WooCommerce site running the vulnerable plugin (plugin enumeration, asset paths, or known endpoint probing).
- Craft the request — Attacker builds a single HTTP POST request to any URL on the target site, setting the
xpv_imageparameter to a malicious payload. - Bypass the (non-existent) gate — The
wp_loadedhandler processes the request; the commented-out nonce/auth check never runs, so there is no authentication barrier to cross. - Trigger rendering — The unsanitized
xpv_imagevalue is embedded into an HTML template and passed to Dompdf for PDF rendering with PHP execution enabled. - Achieve RCE — The attacker's payload executes server-side during rendering, giving them code execution in the context of the web server.
- Post-exploitation — From there, the attacker can plant a persistent webshell, exfiltrate the WordPress/WooCommerce database, or use the compromised host as a pivot point.
Mitigation
Immediate Actions
- A patched version has not been independently confirmed as of this writing. Public advisories (Wordfence, Patchstack) recommend site owners update beyond 2.16.2 as soon as a fixed release is available — check the plugin's WordPress.org changelog before assuming a fix is live.
- Until a confirmed fix is available, disable or remove the 3D Product configurator for WooCommerce plugin. Given the unauthenticated, zero-interaction nature of this flaw, this is the only mitigation that fully closes the exposure.
- If the plugin cannot be removed immediately, block POST requests carrying an
xpv_imageparameter at the WAF/reverse-proxy layer as a stopgap — this is a mitigation, not a fix, and should not replace removal or patching.
Detection Opportunities
- Review web server access logs for POST requests containing
xpv_imagefrom unfamiliar or unauthenticated clients, especially to unexpected URLs (the handler fires onwp_loaded, so it can be reached via virtually any site path). - Check for unexpected PHP files, modified theme/plugin files, or new admin accounts created around the time of any suspicious
xpv_imagePOST activity. - Monitor outbound connections and process execution from the web server user for signs of a planted webshell or reverse shell.
Defence-in-Depth
- Run WooCommerce plugin inventories regularly and prioritize patching or removing low-install, infrequently maintained plugins — this plugin's only prior CVE (CVE-2022-1953, Arbitrary File Deletion) suggests a pattern of weaker security review.
- Disable PHP execution within any Dompdf (or similar HTML-to-PDF) rendering sandbox used by third-party plugins, independent of this specific flaw.
- Apply the principle of least exposure: where a plugin's functionality doesn't need to be reachable by anonymous visitors, front it with authentication at the web server or WAF layer rather than relying solely on the plugin's own checks.
Background
3D Product configurator for WooCommerce is a niche WooCommerce add-on from vendor Expivi that lets shoppers visually customize products in 3D before checkout, with the configured result rendered into a PDF quote or order document. That PDF-rendering path — built on Dompdf — is also where this vulnerability lives: a single commented-out security check turned a routine image-parameter handler into a direct, unauthenticated route to server-side code execution. The plugin's only previous CVE (CVE-2022-1953, Arbitrary File Deletion, CVSS 5.4) was lower severity, but the pattern — insufficient input handling in a WooCommerce-adjacent plugin — is a recurring theme in the WordPress plugin ecosystem. Low install counts don't equal low risk: any site running an affected version is fully exposed regardless of the plugin's overall popularity.