CVE-2026-8778: MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the miplwcuploadfile function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require a WordPress account or other prior access?
No. The vulnerability is described as exploitable by unauthenticated attackers, with no privileges or user interaction indicated by the provided vector.
Is remote code execution confirmed as the direct outcome?
The reported impact is arbitrary file upload. The data states that this may make remote code execution possible, but it does not confirm that code execution is guaranteed in every affected deployment.
Which plugin versions should be treated as potentially affected?
The supplied title lists versions through 1.2.2, while the description says all versions through and including 1.2.1. This discrepancy means environments using either 1.2.1 or 1.2.2 should be investigated rather than relying on the description alone for version scoping.