CVE-2026-103889: Unsigned Code Execution in expivi Plugin

This text was generated using artificial intelligence (AI).CVE-2026-103889 affects the WordPress plugin 3D Product Configurator for WooCommerce by expivi. According to Wordfence, the vulnerability has a CVSS score of 9.8. Affected are plugin versions up to and including 2.16.2.

The vulnerability can allow unauthenticated code execution on the server. Therefore, for exposed WordPress installations with the embedded plugin, the patch status should be checked promptly.

Are my systems affected? Check now →