PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103889 expivi CVE debrief

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled.

Vendor
expivi
Product
3D Product configurator for WooCommerce
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Administrators of WordPress sites using the 3D Product configurator for WooCommerce plugin, security teams responsible for monitoring and patching vulnerabilities, and developers who may need to verify and remediate affected code.

Why it matters

CVE-2026-103889 is a critical vulnerability in the 3D Product configurator for WooCommerce plugin for WordPress, allowing for unauthenticated remote code execution. Administrators and security teams should prioritize patching and verification to prevent potential exploitation and impact on site security and data integrity.

  • Potential for unauthenticated remote code execution on affected systems
  • Need for immediate patching to prevent exploitation
  • Potential impact on site security and data integrity
  • Verification of wp_loaded handler and xpv_image parameter sanitization required

Technical summary

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled.

Defensive priority

High priority for patching and verification

Recommended defensive actions

  • Patch the 3D Product configurator for WooCommerce plugin to version greater than 2.16.2
  • Verify that the wp_loaded handler has proper authentication and nonce checks
  • Ensure proper sanitization of the xpv_image POST parameter
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected versions and parameters. However, there is limited information on potential exploits or attacks. To verify, defenders should check for affected product deployments, review official advisories, and monitor for exploitation attempts. The vulnerability allows unauthenticated remote code execution via the 'xpv_image' parameter, with no authentication and nonce checks, and no sanitization of the POST parameter.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103889 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103889

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103889 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103889

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • 3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'x

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103889.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/templates/pdf/pdf-configuration-details.phtml

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/woocommerce/class-expivi-cart-manager.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/pdf/class-pdf.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.