The MIPL Grouped Checkout Fields for WooCommerce, Customize & Organize Checkout Fields.
The MIPL Grouped Checkout Fields plugin lets anyone upload files to a WordPress store. An uploaded file may let an attacker run commands on the site's server.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Not confirmedLast checked today
- Affected versions
- through 1.2.2
- Weakness
- CWE-434Unrestricted Upload of Dangerous File Type
- Exploit likelihood
- 0.62% in 30 daysEPSS, higher than 48% of known flaws
- Affects
- MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-75934ENISA vulnerability database
How it works
- An unauthenticated attacker sends a file through the plugin's upload feature.
- The plugin does not properly check the file type, allowing arbitrary files on the site's server.
- An uploaded file may then make remote code execution possible.
What to do
Check the installed MIPL Grouped Checkout Fields version and compare it with the CVE record. The record lists versions through 1.2.2 as affected, while its description lists versions through 1.2.1.
Follow the CVE record and its linked Wordfence advisory for the documented fix or mitigation.
Technical details
Affected software: MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fieldsby mulika
CVE-2026-8778 affects MIPL Grouped Checkout Fields for WooCommerce. The authoritative record lists versions through 1.2.2 as affected, while its description names versions through 1.2.1, creating an inconsistent boundary. The flaw allows unauthenticated arbitrary file uploads and may enable remote code execution.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- wordfence.com · ac1257a9-7c8e-43aa-b21a-93a77b456aa4 third party advisory technical description NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-8778 third party advisory vdb entry
- cvefeed.io · CVE-2026-8778 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-8778
- plugins.trac.wordpress.org · mipl-wc-checkout-fields.php (1.2.1) L260 NVD
- plugins.trac.wordpress.org · mipl-wc-checkout-fields.php (trunk) L260 NVD
- plugins.trac.wordpress.org · class-mipl-wc-cf-checkout-block.php (1.2.1) L415 NVD
- plugins.trac.wordpress.org · class-mipl-wc-cf-checkout-block.php (trunk) L415 NVD
- plugins.trac.wordpress.org · changeset NVD