CVE-2026-103889: Unsigned Code Execution in expivi Plugin
This text was generated using artificial intelligence (AI).CVE-2026-103889 affects the WordPress plugin 3D Product Configurator for WooCommerce by expivi. According to Wordfence, the vulnerability has a CVSS score of 9.8. Affected are plugin versions up to and including 2.16.2.
The vulnerability can allow unauthenticated code execution on the server. Therefore, for exposed WordPress installations with the embedded plugin, the patch status should be checked promptly.
For remediation, version 2.16.3 or a newer version is available. The patch was released in early October 2026 according to the available information; the disclosure of the CVE followed on October 10, 2026.
Technical background
The vulnerability lies in the processing of the parameter xpv_image. The affected handler lacks effective authentication and nonce checks. The existing check is enclosed in a block comment.
The parameter is not sanitized and is transferred into an HTML template processed by Dompdf. In this processing, PHP execution is enabled. As a result, an unauthenticated attacker can execute code on the affected server. The documented attack path requires a single unauthenticated POST request to a URL of the website.
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) classified. An active exploitation is not documented according to the available information.
Prioritization and measures
Organizations should first determine whether the plugin is used on publicly accessible WordPress installations. Particularly relevant are online shops where the product configurator is actively integrated.
Recommended measures:
Update the expivi plugin to version 2.16.3 or newer.
Check patch status and vulnerability on WordPress installations.
Prioritize and mitigate affected systems based on their public accessibility.
Establish continuous vulnerability and vendor risk monitoring.
The update addresses the documented error in the plugin. Checking publicly accessible systems helps to assign affected installations to the responsible teams.
Operators of publicly accessible WooCommerce shops in Germany and Austria are subject to the GDPR reporting obligation under Art. 33 GDPR (72-hour deadline to the competent supervisory authority) in the event of a successful compromise related to personal data. For NIS-2 obligated organizations — implemented in Germany via the BSIG, in Austria via the NISG — the recording of deployed web plugins is part of the asset inventory. Swiss organizations check their reporting obligations in accordance with the revised Information Security Act (ISG) against the BACS.
Visibility of external web applications
The vulnerability affects a WordPress plugin that can be provided under an organization's domain and may be externally recognizable. LocateRisk can make publicly accessible assets and deployed software visible — including forgotten subdomains, unregistered cloud instances, and external web applications operating outside the central patch process. This supports the identification of online shops and WordPress instances that are relevant for checking the patch status.
However, the external visibility of a plugin does not demonstrate the specifically installed vulnerable version. Whether an installation of CVE-2026-103889 is affected must be confirmed through internal checking of plugin version and patch status. Clear responsibilities, prioritization of accessible systems, and documentation of the update are part of the operational handling.
Am I affected?
The affected version is expivi 3D Product Configurator for WooCommerce in the versions mentioned above; the vulnerability was fixed in 2.16.3. If you want to know whether expivi 3D Product Configurator for WooCommerce is even visible in your own externally accessible infrastructure, you can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-103889 is a critical vulnerability in the WordPress plugin 3D Product Configurator for WooCommerce from expivi. It allows unauthorized attackers to execute arbitrary code on the affected server via a single POST request. The CVSS score is 9.8 (critical).
The expivi plugin should be updated to version 2.16.3 or newer. Additionally, it is advisable to check whether the plugin is actively integrated on publicly accessible systems, as well as to establish continuous monitoring of the patch status for used WordPress plugins.
As of: October 10, 2026. This article is for general informational purposes and does not constitute legal, security, or action advice in individual cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the accuracy, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-103889
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.