Skip to content
feed: live
0dayNews
wordpress

Three Critical WooCommerce Plugins Need Patching

An RCE, an auth bypass, and an arbitrary file deletion in three WooCommerce plugins this week. All rated CVSS 9.1 or higher. Patch all three now.

Three Critical WooCommerce Plugins Need Patching
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

Three WooCommerce plugins disclosed critical vulnerabilities this week: an unauthenticated remote code execution (RCE) at CVSS 9.8, an authentication bypass at CVSS 9.8, and an arbitrary file deletion at CVSS 9.1. All three affect plugins running on public-facing e-commerce stores. Update now.

CVE-2026-103889: 3D Product Configurator RCE (CVSS 9.8)

The 3D Product Configurator plugin for WooCommerce (slug: expivi) had an unauthenticated RCE in all versions up to and including 2.16.2. The flaw is in the plugin’s image-handling code. User input passed via the xpv_image parameter reaches a file operation without adequate validation, and an unauthenticated attacker can execute arbitrary code on the server. No credentials, no user interaction.

RCE on a WooCommerce host means full access to the PHP environment, the database, and stored customer data. Version 2.16.3 fixes the issue. Update this one first.

NVD: CVE-2026-103889

CVE-2026-104803: WPCOM Member authentication bypass (CVSS 9.8)

WPCOM Member had an authentication bypass in all versions up to and including 1.7.27. The social login callback handler uses uuid and code parameters to authenticate users without confirming those values came from a real OAuth flow. An attacker who knows a valid UUID for any registered user can authenticate as that user without going through an OAuth provider.

On a membership or e-commerce site, any registered account is at risk. Order history, stored payment details, and member data are all reachable from a taken-over session. Fix is in version 1.7.28 or later.

NVD: CVE-2026-104803

CVE-2026-104801: PPOM Product Addons file deletion (CVSS 9.1)

The PPOM Product Addons and Custom Fields for WooCommerce plugin had an arbitrary file deletion flaw in all versions up to and including 34.0.10. The rename_files function did not enforce file path constraints, letting an attacker delete files outside the plugin’s intended scope. File deletion can knock out configuration files, disable application components, or wipe logs. Update to 34.0.11 or later.

NVD: CVE-2026-104801

What to do

Patch order by risk:

  1. 3D Product Configurator (expivi) first: unauthenticated RCE with no preconditions is the most direct server-level risk.
  2. WPCOM Member second: authentication bypass at CVSS 9.8 puts every registered account on the site at risk.
  3. PPOM Product Addons third: CVSS 9.1, file deletion without write access, still critical but lower immediate exploitation risk than the two above.

If you cannot patch immediately, disable the affected plugins until you can. A disabled plugin breaks site functionality but does not leave the attack surface open.

WordPress plugin updates are available through the dashboard under Plugins > Installed Plugins. For managed installs, wp plugin update --all via WP-CLI handles the batch.

WooCommerce plugin disclosures have been arriving at a steady pace. Four CVSS 9.8 auth bypass flaws in WooCommerce plugins were disclosed last week. Weekly plugin update checks should be part of your standard maintenance cycle. See the WordPress topic hub for ongoing coverage.

Related CVEs
  • [ CRITICAL ]CVE-2026-1038893D Product Configurator for WooCommerce Unauthenticated RCE
  • [ CRITICAL ]CVE-2026-104803WPCOM Member Authentication Bypass via Social Login Callback
  • [ CRITICAL ]CVE-2026-104801PPOM Product Addons for WooCommerce Arbitrary File Deletion

Found this useful? Share it.