<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>3D Product Configurator for WooCommerce (&lt;= 2.16.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/3d-product-configurator-for-woocommerce--2.16.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 05:34:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/3d-product-configurator-for-woocommerce--2.16.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in 3D Product Configurator for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103889/</link><pubDate>Sat, 10 Oct 2026 05:34:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-103889/</guid><description>The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to unauthenticated remote code execution via the xpv_image parameter in versions up to 2.16.2.</description><content:encoded><![CDATA[<p>The 3D Product configurator for WooCommerce plugin for WordPress (versions 2.16.2 and earlier) is affected by a critical remote code execution vulnerability (CVE-2026-103889). The flaw resides within the plugin's 'wp_loaded' action handler, where an authentication and nonce check were mistakenly commented out, rendering the endpoint reachable by any unauthenticated user.</p>
<p>The plugin processes the 'xpv_image' POST parameter without any sanitization. This value is subsequently passed to the Dompdf library, which is configured with PHP execution enabled. By crafting a specific HTTP POST request, an unauthenticated attacker can inject arbitrary PHP code that the server will execute upon rendering the HTML template. This vulnerability allows for full remote code execution, granting attackers the ability to compromise the WordPress environment, exfiltrate data, or install persistent backdoors.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary code on the underlying web server. This can lead to complete site takeover, unauthorized access to WooCommerce order and customer databases, and the potential for lateral movement within the hosting infrastructure. Organizations relying on this plugin for product visualization face severe risk of site compromise and data loss.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the '3D Product configurator for WooCommerce' plugin to the latest version immediately to remediate CVE-2026-103889.</li>
<li>If an update is not immediately available, disable the plugin until a patch is applied.</li>
<li>Enable web application firewall (WAF) rules to inspect HTTP POST requests targeting WordPress sites for suspicious PHP code injection patterns in the 'xpv_image' parameter.</li>
<li>Monitor web server logs for high volumes of POST requests to site URLs that do not correspond to typical user interaction with the plugin.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>