Arbitrary File Upload Vulnerability in WooCommerce Plugin by MIPL Group
CVE-2026-8778

9.8CRITICAL

What is CVE-2026-8778?

The MIPL Grouped Checkout Fields for WooCommerce plugin is vulnerable to arbitrary file uploads due to inadequate file type validation in the mipl_wc_upload_file function. This weakness allows unauthenticated attackers to upload files to the server, potentially leading to remote code execution. All versions up to and including 1.2.1 are susceptible, making it essential for site administrators using this plugin to apply necessary updates and bolster their security measures.

Affected Version(s)

MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields. 0 <= 1.2.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Farrukh Ziyaev
.