Update 3D Product Configurator Past 2.16.2 Now to Fix Critical Unauthenticated RCE Flaw
The NVD rates this remote code execution vulnerability in the 3D Product Configurator plugin as critical due to missing authentication checks.

Key points
- The National Vulnerability Database rates CVE-2026-103889 as critical with a CVSS score of 9.8.
- All versions of the 3D Product Configurator for WooCommerce plugin up to and including 2.16.2 are affected by this flaw.
- Attackers can execute code on the server by sending a single unauthenticated POST request to any URL on the site.
System administrators must immediately assess their WordPress installations for the 3D Product Configurator for WooCommerce plugin. The National Vulnerability Database has assigned CVE-2026-103889 to this vulnerability, rating it critical with a CVSS score of 9.8. This high severity score reflects the ease with which an attacker can compromise the server hosting the website.
In plain English
The vulnerability allows remote code execution without any form of authentication. According to the NVD record, the issue stems from missing authentication and nonce checks on the wp_loaded handler. Additionally, the plugin fails to sanitize the 'xpv_image' POST parameter before echoing it unescaped into a Dompdf-rendered HTML template.
This combination of flaws enables an attacker to inject malicious code. The NVD notes that the only nonce and authentication check in the handler is enclosed in a block comment. Because there is no replacement check, the endpoint remains reachable via a single unauthenticated POST request to any URL on the site.
The background
The 3D Product Configurator for WooCommerce plugin is developed by expivi. The NVD record specifies that all versions up to and including 2.16.2 are vulnerable to this remote code execution flaw. The weakness is classified under CWE-434, which relates to unrestricted upload of file with dangerous type.
The vulnerability allows unauthenticated attackers to execute arbitrary code on the server. This means anyone on the internet can potentially take full control of the server if they identify a site using the affected plugin. The lack of input sanitization and authentication makes this a significant risk for any public-facing WordPress site.
What changes now
Security teams should prioritize scanning their WordPress environments for this specific plugin. The NVD record explicitly states that versions up to 2.16.2 are affected. Administrators need to verify the current version installed on their servers to determine if they are at risk from this critical remote code execution vulnerability.
If a site is running an affected version, immediate action is required to mitigate the risk. The nature of the flaw means that automated scanning tools could easily exploit it. System administrators must ensure that their inventory of plugins is accurate and up-to-date to prevent unauthorized server access through this vector.
What to do and how to stay safe: WooCommerce
- Scan all WordPress installations to identify if the 3D Product Configurator for WooCommerce plugin is installed and check its version against the affected range up to 2.16.2.
- Review server logs for any unusual POST requests to the 'xpv_image' parameter or other endpoints associated with this plugin to detect potential exploitation attempts.
- Restrict access to the WordPress admin area and plugin endpoints using IP whitelisting or web application firewalls to reduce the attack surface until a fix is applied.
- Monitor the vendor's official channels for a security update and apply it immediately once available to patch the missing authentication and sanitization flaws.
Step-by-step guide: Risk-Based Vulnerability Management: Benefits, Limits, and Reality
General security guidance from the Vector Update newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Which versions of the 3D Product Configurator plugin are affected by CVE-2026-103889?
All versions up to and including 2.16.2 are vulnerable to this remote code execution flaw according to the NVD record.
What is the severity rating for this vulnerability?
The National Vulnerability Database rates CVE-2026-103889 as critical with a CVSS score of 9.8.
How can an attacker exploit this vulnerability?
An unauthenticated attacker can execute code on the server by sending a single POST request to any URL on the site, exploiting the missing authentication checks.



