PatchSiren cyber security CVE debrief
CVE-2026-103889 expivi CVE debrief
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled.
- Vendor
- expivi
- Product
- 3D Product configurator for WooCommerce
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Administrators of WordPress sites using the 3D Product configurator for WooCommerce plugin, security teams responsible for monitoring and patching vulnerabilities, and developers who may need to verify and remediate affected code.
Why it matters
CVE-2026-103889 is a critical vulnerability in the 3D Product configurator for WooCommerce plugin for WordPress, allowing for unauthenticated remote code execution. Administrators and security teams should prioritize patching and verification to prevent potential exploitation and impact on site security and data integrity.
- Potential for unauthenticated remote code execution on affected systems
- Need for immediate patching to prevent exploitation
- Potential impact on site security and data integrity
- Verification of wp_loaded handler and xpv_image parameter sanitization required
Technical summary
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled.
Defensive priority
High priority for patching and verification
Recommended defensive actions
- Patch the 3D Product configurator for WooCommerce plugin to version greater than 2.16.2
- Verify that the wp_loaded handler has proper authentication and nonce checks
- Ensure proper sanitization of the xpv_image POST parameter
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected versions and parameters. However, there is limited information on potential exploits or attacks. To verify, defenders should check for affected product deployments, review official advisories, and monitor for exploitation attempts. The vulnerability allows unauthenticated remote code execution via the 'xpv_image' parameter, with no authentication and nonce checks, and no sanitization of the POST parameter.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103889 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103889
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103889 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103889
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'x
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103889.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/templates/pdf/pdf-configuration-details.phtml
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/woocommerce/class-expivi-cart-manager.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/expivi/tags/2.16.2/classes/pdf/class-pdf.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.