Unauthenticated Remote Code Execution in 3D Product Configurator for WooCommerce
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to unauthenticated remote code execution via the xpv_image parameter in versions up to 2.16.2.
CVE search metadata
CVE search record: CVE-2026-103889. Severity: critical. CVSS: 9.8. KEV: no. Product: 3D Product configurator for WooCommerce (<= 2.16.2). Brief: Unauthenticated Remote Code Execution in 3D Product Configurator for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103889/
The 3D Product configurator for WooCommerce plugin for WordPress (versions 2.16.2 and earlier) is affected by a critical remote code execution vulnerability (CVE-2026-103889). The flaw resides within the plugin's 'wp_loaded' action handler, where an authentication and nonce check were mistakenly commented out, rendering the endpoint reachable by any unauthenticated user.
The plugin processes the 'xpv_image' POST parameter without any sanitization. This value is subsequently passed to the Dompdf library, which is configured with PHP execution enabled. By crafting a specific HTTP POST request, an unauthenticated attacker can inject arbitrary PHP code that the server will execute upon rendering the HTML template. This vulnerability allows for full remote code execution, granting attackers the ability to compromise the WordPress environment, exfiltrate data, or install persistent backdoors.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary code on the underlying web server. This can lead to complete site takeover, unauthorized access to WooCommerce order and customer databases, and the potential for lateral movement within the hosting infrastructure. Organizations relying on this plugin for product visualization face severe risk of site compromise and data loss.
Recommendation
- Update the '3D Product configurator for WooCommerce' plugin to the latest version immediately to remediate CVE-2026-103889.
- If an update is not immediately available, disable the plugin until a patch is applied.
- Enable web application firewall (WAF) rules to inspect HTTP POST requests targeting WordPress sites for suspicious PHP code injection patterns in the 'xpv_image' parameter.
- Monitor web server logs for high volumes of POST requests to site URLs that do not correspond to typical user interaction with the plugin.
Immediate actions
Patch 3D Product configurator for WooCommerce to latest version.
Threat Hunt
Search web logs for suspicious POST requests containing PHP tags or system commands.
Data: webserver_logs
Mitigations
Disable plugin until patched.
CVE-2026-103889
Detection coverage 1
Detect CVE-2026-103889 Exploitation - Unauthenticated RCE via xpv_image
criticalDetects exploitation of CVE-2026-103889 by monitoring for POST requests containing PHP code structures in the xpv_image parameter.
Detection queries are available on the platform. Get full rules →