CVE-2026-103889 - 3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'xpv_image' Parameter
CVE ID :CVE-2026-103889 Published : Oct. 10, 2026, 4:26 a.m. | 1 hour, 3 minutes ago Description :The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This...