Junglewise Threat Intelligence

CVE-2026-8778: MIPL Grouped Checkout Fields for WooCommerce arbitrary file upload

CVE-2026-8778 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Executive brief

The MIPL Grouped Checkout Fields for WooCommerce plugin, used to customize and organize checkout forms in online stores, is vulnerable to arbitrary file uploads. An unauthenticated attacker can upload malicious files to the server without any restrictions, potentially executing code and compromising the entire website and customer data.

Technical details

The vulnerability is an arbitrary file upload flaw in the `mipl_wc_upload_file` function that lacks proper file type validation. The vulnerable endpoint is accessible to unauthenticated users, allowing attackers to bypass file upload restrictions and place executable files on the server. This can lead to remote code execution (RCE), enabling full server compromise. Affected versions include 1.2.1 and earlier. Patches or fixes should be checked via the official WordPress plugin repository.

Affected products

  • MIPL Grouped Checkout Fields for WooCommerce up to and including 1.2.1

Timeline

  • 2026-09-11: disclosed

References