CRITICAL 9.8 CVE-2026-8778 Published 11 Sept 2026

WooCommerce Plugin Arbitrary File Upload

Worried this affects one of your servers?

The MIPL Grouped Checkout Fields for WooCommerce plugin is vulnerable to arbitrary file uploads due to missing file type validation.

This allows unauthenticated attackers to upload arbitrary files on the affected site's server, potentially enabling remote code execution.

Reference: CVE-2026-8778 on NVD

← Back to Security News