WordPress: unauthenticated RCE in 3D Product configurator for WooCommerce (CVE-2026-103889, CVSS 9.8), Avada Builder arbitrary action-hook invocation that can wipe trashed content (CVE-2026-97670, 9.1) and PPOM file deletion/read (CVE-2026-104801, 9.1) — update to 2.16.3, 7.16.2 and 34.0.11
Wordfence, acting as CVE numbering authority, disclosed three unauthenticated WordPress flaws on 9 October 2026; the CVE records were published on 10 October. CVE-2026-103889 (CVSS 9.8) affects the 3D Product configurator for WooCommerce plugin (Expivi, slug expivi) up to and including 2.16.2: the nonce and authentication check on its wp_loaded handler is commented out, and the xpv_image POST value is echoed unescaped into a Dompdf template rendered with PHP execution enabled, so a single unauthenticated POST to any URL on the site can run code on the server. The plugin has about 100 active installs on WordPress.org; its 2.16.3 changelog (1 October) lists a security fix. CVE-2026-97670 (CVSS 9.1) affects the Avada (Fusion) Builder plugin bundled with the commercial Avada theme, up to 7.16.1: the public form-submit endpoint lets a form-field value pick a WordPress action hook to run, because the trust check only inspects the args parameter and never the formData the endpoint parses. Unauthenticated visitors can trigger arbitrary action hooks; Wordfence verified one request permanently deleting trashed posts, pages and comments through core wp_scheduled_delete, with denial of service and further writes possible through other hooks. It needs a published Avada form using AJAX submission with a notification email that includes an [all_fields] or [field] placeholder, which is the default form setup. ThemeFusion released Avada 7.16.2 on 30 September with fixes for six security issues, crediting Wordfence and Patchstack. CVE-2026-104801 (CVSS 9.1) affects PPOM – Product Addons & Custom Fields for WooCommerce (20,000+ active installs) up to 34.0.10: weak path checks in its rename_files function let unauthenticated attackers move any file on the server into the public uploads/ppom_files/confirmed folder, which deletes it from its original place (deleting wp-config.php can lead to site takeover) and exposes its contents. PPOM 34.0.11 (7 October) fixes file uploads allowing visitors to delete files outside the uploads folder. No exploitation reported. Primary: CVE records (Wordfence CNA); vendor: Avada security update post and WordPress.org changelogs.
- Product
- WordPress plugins: 3D Product configurator for WooCommerce (Expivi); Avada (Fusion) Builder (ThemeFusion, bundled with the Avada theme); PPOM – Product Addons & Custom Fields for WooCommerce
- Versions
- 3D Product configurator for WooCommerce 2.16.2 and earlier; Avada Builder 7.16.1 and earlier; PPOM 34.0.10 and earlier
- CVSS
- (CVE-2026-103889); 9.1 (CVE-2026-97670); 9.1 (CVE-2026-104801) — CVSS 3.1, Wordfence
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Update 3D Product configurator for WooCommerce to 2.16.3 or later, Avada (theme and Avada Builder) to 7.16.2 or later and PPOM to 34.0.11 or later. PPOM sites: check wp-content/uploads/ppom_files/confirmed/ for files that don't belong there (wp-config.php, .htaccess, backups) and rotate database and salt secrets if any appear. Avada sites: check whether trashed content vanished unexpectedly before patching. 3D configurator sites: look for unexpected PHP files or admin users.
Primary: CVE-2026-103889 — 3D Product configurator for WooCommerce <= 2.16.2 unauthenticated RCE via xpv_image (Wordfence CNA, published 10 Oct 2026); see also CVE-2026-97670 and CVE-2026-104801 · Vendor: ThemeFusion — Avada 7.16.2 security update (30 Sep 2026): six security fixes · CVE: CVE-2026-103889, CVE-2026-97670, CVE-2026-104801 · PPOM changelog — 34.0.11 (7 Oct 2026): fixed file uploads allowing visitors to delete files outside uploads folder
