Arbitrary File Upload Vulnerability in WooCommerce Plugin by MIPL Group
CVE-2026-8778
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-8778?
The MIPL Grouped Checkout Fields for WooCommerce plugin is vulnerable to arbitrary file uploads due to inadequate file type validation in the mipl_wc_upload_file function. This weakness allows unauthenticated attackers to upload files to the server, potentially leading to remote code execution. All versions up to and including 1.2.1 are susceptible, making it essential for site administrators using this plugin to apply necessary updates and bolster their security measures.
Affected Version(s)
MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields. 0 <= 1.2.2