Skip to content
Threat Feed
critical advisory

Unauthenticated Remote Code Execution in 3D Product Configurator for WooCommerce

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to unauthenticated remote code execution via the xpv_image parameter in versions up to 2.16.2.

CVE search metadata

CVE search record: CVE-2026-103889. Severity: critical. CVSS: 9.8. KEV: no. Product: 3D Product configurator for WooCommerce (<= 2.16.2). Brief: Unauthenticated Remote Code Execution in 3D Product Configurator for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103889/

The 3D Product configurator for WooCommerce plugin for WordPress (versions 2.16.2 and earlier) is affected by a critical remote code execution vulnerability (CVE-2026-103889). The flaw resides within the plugin's 'wp_loaded' action handler, where an authentication and nonce check were mistakenly commented out, rendering the endpoint reachable by any unauthenticated user.

The plugin processes the 'xpv_image' POST parameter without any sanitization. This value is subsequently passed to the Dompdf library, which is configured with PHP execution enabled. By crafting a specific HTTP POST request, an unauthenticated attacker can inject arbitrary PHP code that the server will execute upon rendering the HTML template. This vulnerability allows for full remote code execution, granting attackers the ability to compromise the WordPress environment, exfiltrate data, or install persistent backdoors.

Impact

Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary code on the underlying web server. This can lead to complete site takeover, unauthorized access to WooCommerce order and customer databases, and the potential for lateral movement within the hosting infrastructure. Organizations relying on this plugin for product visualization face severe risk of site compromise and data loss.

Recommendation

  • Update the '3D Product configurator for WooCommerce' plugin to the latest version immediately to remediate CVE-2026-103889.
  • If an update is not immediately available, disable the plugin until a patch is applied.
  • Enable web application firewall (WAF) rules to inspect HTTP POST requests targeting WordPress sites for suspicious PHP code injection patterns in the 'xpv_image' parameter.
  • Monitor web server logs for high volumes of POST requests to site URLs that do not correspond to typical user interaction with the plugin.

Immediate actions

Patch 3D Product configurator for WooCommerce to latest version.

IT Operations 24h

Threat Hunt

Search web logs for suspicious POST requests containing PHP tags or system commands.

T1190 high high confidence hunt now

Data: webserver_logs

Mitigations

Disable plugin until patched.

immediate IT Operations

CVE-2026-103889

Detection coverage 1

Detect CVE-2026-103889 Exploitation - Unauthenticated RCE via xpv_image

critical

Detects exploitation of CVE-2026-103889 by monitoring for POST requests containing PHP code structures in the xpv_image parameter.

sigma tactics: execution, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →