CVE-2026-103889 | expivi 3D Product Configurator Plugin up to 2.16.2 on WordPress Image Processing wp_loaded xpv_image missing authentication

SecurityVulns

A vulnerability was found in expivi 3D Product Configurator Plugin up to 2.16.2 on WordPress. It has been rated as critical. This vulnerability affects the function wp_loaded of the component Image Processing. The manipulation of the argument xpv_image leads to missing authentication.

This vulnerability is referenced as CVE-2026-103889. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More