Vulnerability
Published 2026-10-09
Verified 2026-10-10

WordPress: unauthenticated RCE in 3D Product configurator for WooCommerce (CVE-2026-103889, CVSS 9.8), Avada Builder arbitrary action-hook invocation that can wipe trashed content (CVE-2026-97670, 9.1) and PPOM file deletion/read (CVE-2026-104801, 9.1) — update to 2.16.3, 7.16.2 and 34.0.11

Wordfence, acting as CVE numbering authority, disclosed three unauthenticated WordPress flaws on 9 October 2026; the CVE records were published on 10 October. CVE-2026-103889 (CVSS 9.8) affects the 3D Product configurator for WooCommerce plugin (Expivi, slug expivi) up to and including 2.16.2: the nonce and authentication check on its wp_loaded handler is commented out, and the xpv_image POST value is echoed unescaped into a Dompdf template rendered with PHP execution enabled, so a single unauthenticated POST to any URL on the site can run code on the server. The plugin has about 100 active installs on WordPress.org; its 2.16.3 changelog (1 October) lists a security fix. CVE-2026-97670 (CVSS 9.1) affects the Avada (Fusion) Builder plugin bundled with the commercial Avada theme, up to 7.16.1: the public form-submit endpoint lets a form-field value pick a WordPress action hook to run, because the trust check only inspects the args parameter and never the formData the endpoint parses. Unauthenticated visitors can trigger arbitrary action hooks; Wordfence verified one request permanently deleting trashed posts, pages and comments through core wp_scheduled_delete, with denial of service and further writes possible through other hooks. It needs a published Avada form using AJAX submission with a notification email that includes an [all_fields] or [field] placeholder, which is the default form setup. ThemeFusion released Avada 7.16.2 on 30 September with fixes for six security issues, crediting Wordfence and Patchstack. CVE-2026-104801 (CVSS 9.1) affects PPOM – Product Addons & Custom Fields for WooCommerce (20,000+ active installs) up to 34.0.10: weak path checks in its rename_files function let unauthenticated attackers move any file on the server into the public uploads/ppom_files/confirmed folder, which deletes it from its original place (deleting wp-config.php can lead to site takeover) and exposes its contents. PPOM 34.0.11 (7 October) fixes file uploads allowing visitors to delete files outside the uploads folder. No exploitation reported. Primary: CVE records (Wordfence CNA); vendor: Avada security update post and WordPress.org changelogs.

Product
WordPress plugins: 3D Product configurator for WooCommerce (Expivi); Avada (Fusion) Builder (ThemeFusion, bundled with the Avada theme); PPOM – Product Addons & Custom Fields for WooCommerce
Versions
3D Product configurator for WooCommerce 2.16.2 and earlier; Avada Builder 7.16.1 and earlier; PPOM 34.0.10 and earlier
CVSS
(CVE-2026-103889); 9.1 (CVE-2026-97670); 9.1 (CVE-2026-104801) — CVSS 3.1, Wordfence
Exploited in Australia?
unknown
Patch to
Update 3D Product configurator for WooCommerce to 2.16.3 or later, Avada (theme and Avada Builder) to 7.16.2 or later and PPOM to 34.0.11 or later. PPOM sites: check wp-content/uploads/ppom_files/confirmed/ for files that don't belong there (wp-config.php, .htaccess, backups) and rotate database and salt secrets if any appear. Avada sites: check whether trashed content vanished unexpectedly before patching. 3D configurator sites: look for unexpected PHP files or admin users.

Primary: CVE-2026-103889 — 3D Product configurator for WooCommerce <= 2.16.2 unauthenticated RCE via xpv_image (Wordfence CNA, published 10 Oct 2026); see also CVE-2026-97670 and CVE-2026-104801 · Vendor: ThemeFusion — Avada 7.16.2 security update (30 Sep 2026): six security fixes · CVE: CVE-2026-103889, CVE-2026-97670, CVE-2026-104801 · PPOM changelog — 34.0.11 (7 Oct 2026): fixed file uploads allowing visitors to delete files outside uploads folder

vulnerabilities