3D Product Configurator for WooCommerce Unauthenticated RCE
Unauthenticated RCE in the 3D Product Configurator for WooCommerce plugin via the xpv_image parameter. Affects versions up to 2.16.2. CVSS 9.8. Update to 2.16.3.
- Vendor
- Expivi
- Product
- 3D Product Configurator for WooCommerce
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.7%
- Status
- patched
- Published
The 3D Product Configurator for WooCommerce plugin (slug: expivi) contained an unauthenticated remote code execution vulnerability in all versions up to and including 2.16.2.
The flaw is in the plugin’s image-handling logic. User input passed through the xpv_image parameter reaches a file operation without sufficient validation. An unauthenticated attacker can supply crafted input that the server processes as code, gaining full code execution in the web application’s runtime context. No authentication and no user interaction are required.
RCE in a WooCommerce plugin context gives an attacker access to the PHP environment, the database, and any customer data the store holds, including order histories and payment records.
The fix is in version 2.16.3. Update the plugin through the WordPress dashboard under Plugins > Installed Plugins, or run wp plugin update expivi via WP-CLI.
In the same disclosure batch, two other WooCommerce plugins also carry critical flaws: CVE-2026-104803 (WPCOM Member authentication bypass, CVSS 9.8) and CVE-2026-104801 (PPOM Product Addons arbitrary file deletion, CVSS 9.1). See the full coverage article for priority order and remediation steps.
For broader WooCommerce plugin security coverage, see the WordPress topic hub.
