The MIPL Grouped Checkout Fields for WooCommerce, Customize & Organize Checkout Fields.

Published September 11, 2026 CVE-2026-8778

The MIPL Grouped Checkout Fields plugin lets anyone upload files to a WordPress store. An uploaded file may let an attacker run commands on the site's server.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Not confirmedLast checked today
Affected versions
through 1.2.2
Weakness
CWE-434Unrestricted Upload of Dangerous File Type
Exploit likelihood
0.62% in 30 daysEPSS, higher than 48% of known flaws
Affects
MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: yes · Technical impact: total
EU ID
EUVD-2026-75934ENISA vulnerability database

How it works

  • An unauthenticated attacker sends a file through the plugin's upload feature.
  • The plugin does not properly check the file type, allowing arbitrary files on the site's server.
  • An uploaded file may then make remote code execution possible.

What to do

Check the installed MIPL Grouped Checkout Fields version and compare it with the CVE record. The record lists versions through 1.2.2 as affected, while its description lists versions through 1.2.1.

Follow the CVE record and its linked Wordfence advisory for the documented fix or mitigation.

Technical details

Affected software: MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fieldsby mulika

CVE-2026-8778 affects MIPL Grouped Checkout Fields for WooCommerce. The authoritative record lists versions through 1.2.2 as affected, while its description names versions through 1.2.1, creating an inconsistent boundary. The flaw allows unauthenticated arbitrary file uploads and may enable remote code execution.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator