Product
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to unauthenticated remote code execution via the xpv_image parameter in versions up to 2.16.2.