{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/3d-product-configurator-for-woocommerce--2.16.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:3d_product_configurator_for_woocommerce_project:3d_product_configurator_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-103889"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["3D Product configurator for WooCommerce (\u003c= 2.16.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe 3D Product configurator for WooCommerce plugin for WordPress (versions 2.16.2 and earlier) is affected by a critical remote code execution vulnerability (CVE-2026-103889). The flaw resides within the plugin's 'wp_loaded' action handler, where an authentication and nonce check were mistakenly commented out, rendering the endpoint reachable by any unauthenticated user.\u003c/p\u003e\n\u003cp\u003eThe plugin processes the 'xpv_image' POST parameter without any sanitization. This value is subsequently passed to the Dompdf library, which is configured with PHP execution enabled. By crafting a specific HTTP POST request, an unauthenticated attacker can inject arbitrary PHP code that the server will execute upon rendering the HTML template. This vulnerability allows for full remote code execution, granting attackers the ability to compromise the WordPress environment, exfiltrate data, or install persistent backdoors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary code on the underlying web server. This can lead to complete site takeover, unauthorized access to WooCommerce order and customer databases, and the potential for lateral movement within the hosting infrastructure. Organizations relying on this plugin for product visualization face severe risk of site compromise and data loss.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the '3D Product configurator for WooCommerce' plugin to the latest version immediately to remediate CVE-2026-103889.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately available, disable the plugin until a patch is applied.\u003c/li\u003e\n\u003cli\u003eEnable web application firewall (WAF) rules to inspect HTTP POST requests targeting WordPress sites for suspicious PHP code injection patterns in the 'xpv_image' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for high volumes of POST requests to site URLs that do not correspond to typical user interaction with the plugin.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T05:34:10Z","date_published":"2026-10-10T05:34:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103889/","summary":"The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to unauthenticated remote code execution via the xpv_image parameter in versions up to 2.16.2.","title":"Unauthenticated Remote Code Execution in 3D Product Configurator for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103889/"}],"language":"en","title":"CraftedSignal Threat Feed - 3D Product Configurator for WooCommerce (\u003c= 2.16.2)","version":"https://jsonfeed.org/version/1.1"}