CVE-2026-8778: Unauthenticated file upload in WooCommerce plugin

This text was generated using artificial intelligence (AI).On September 11, 2026, CVE-2026-8778 for the WordPress plugin MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields published. According to Wordfence, the vulnerability affects all plugin versions up to and including 1.2.1.

The vulnerability allows unauthenticated uploads of arbitrary files via the function mipl_wc_upload_file. This can make code execution possible on the affected WordPress server. Wordfence rates CVE-2026-8778 with a CVSS score of 9.8.

Are my systems affected? Check now →