Sceawere

Vulnerability Detail

CVE-2026-103889UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RCE in 3D Product Configurator

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
expivi
Product
3D Product configurator for WooCommerce
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthenticated attackers to execute code on the server. The only nonce and authentication check in the handler is entirely enclosed in a block comment with no replacement, making the endpoint reachable via a single unauthenticated POST to any URL on the site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T05:16:39.130Z",
  "pubdate": "2026-10-10T05:16:39.130Z",
  "executiveSummary": "The 3D Product configurator for WooCommerce plugin is affected by a critical Remote Code Execution (RCE) vulnerability in versions up to and including 2.16.2. The flaw resides within the plugin's wp_loaded handler, which fails to enforce authentication or nonce validation, effectively exposing sensitive functionality to unauthenticated remote attackers.\nBy manipulating the 'xpv_image' POST parameter, an attacker can inject arbitrary code into an HTML template processed by Dompdf. Because the application executes PHP within this template context, the vulnerability leads to full server-side code execution. This allows an attacker to compromise the entire WordPress installation, access database credentials, exfiltrate sensitive customer data, or pivot into the underlying server infrastructure. Given the lack of required authentication or network-level restrictions, this vulnerability presents a high-severity risk to any organization utilizing the affected plugin version. Immediate action is required to neutralize the exposure, as the lack of existing security controls makes exploitation trivial for any remote threat actor.",
  "technicalDetails": "The vulnerability is rooted in an improperly secured AJAX or hook-based handler triggered during the WordPress 'wp_loaded' action. The developers implemented a security check mechanism, specifically authentication and nonce verification, but rendered it ineffective by wrapping the entire validation logic within a block comment. Consequently, the endpoint remains fully accessible to any unauthenticated user sending a POST request to any URL on the WordPress site.\nThe attack vector involves the 'xpv_image' parameter. The plugin takes the input provided in this parameter and processes it through a Dompdf rendering engine. Crucially, the application fails to sanitize this input, allowing for the injection of malicious payloads that are rendered as part of an HTML template. Because the Dompdf integration context allows for the execution of PHP code within the template engine, the unauthenticated input is interpreted as executable code by the server.\nThe attack flow follows a predictable sequence: First, the attacker identifies a site using the 3D Product configurator for WooCommerce (versions 2.16.2 and below). Second, the attacker constructs a crafted POST request targeting the site, containing the malicious payload within the 'xpv_image' parameter. Third, because the 'wp_loaded' hook lacks authentication checks, the server proceeds to handle the request. Fourth, the malicious PHP code is injected into the Dompdf template context. Fifth, the PHP engine processes the template, resulting in the execution of the injected code on the server operating system. This allows the attacker to execute arbitrary commands with the privileges of the web server user (e.g., www-data).\nPost-exploitation impact is severe, as it grants the attacker full control over the web application environment. This includes the ability to modify core files, install backdoors, manipulate WooCommerce order data, and potentially gain access to the MySQL database containing user credentials and sensitive transaction details. The lack of validation on the 'xpv_image' parameter, combined with the insecure template rendering process, demonstrates a failure to implement defense-in-depth principles for server-side processing."
}
CVE-2026-103889: RCE in 3D Product Configurator (CRITICAL Severity, CVSS: 9.8) | Sceawere