---
id: CVE-2026-8778
title: >-
  MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated
  Arbitrary File Upload
summary: >-
  The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize
  Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads
  due to missing file type validation in the `mipl_wc_upload_file` function in
  all versio…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-434
vendor: mulika
product: >-
  MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout
  Fields.
affected:
  - >-
    mipl_grouped_checkout_fields_for_woocommerce._customize_organize_checkout_fields.
    <= 1.2.2
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T20:11:19.055852Z'
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T20:19:12.419Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-8778'
references:
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/ac1257a9-7c8e-43aa-b21a-93a77b456aa4?source=cve
  - url: >-
      https://plugins.trac.wordpress.org/browser/mipl-wc-checkout-fields/tags/1.2.1/mipl-wc-checkout-fields.php#L260
  - url: >-
      https://plugins.trac.wordpress.org/browser/mipl-wc-checkout-fields/trunk/mipl-wc-checkout-fields.php#L260
  - url: >-
      https://plugins.trac.wordpress.org/browser/mipl-wc-checkout-fields/tags/1.2.1/include/class-mipl-wc-cf-checkout-block.php#L415
  - url: >-
      https://plugins.trac.wordpress.org/browser/mipl-wc-checkout-fields/trunk/include/class-mipl-wc-cf-checkout-block.php#L415
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3552029%40mipl-wc-checkout-fields%2Ftrunk%2Finclude%2Fclass-mipl-wc-cf-checkout-block.php&old=3549283%40mipl-wc-checkout-fields%2Ftrunk%2Finclude%2Fclass-mipl-wc-cf-checkout-block.php&sfp_email=&sfph_mail=
tags:
  - cve.org
epss: 0.00623
epssPercentile: 0.48553
ingestedAt: '2026-09-14T11:11:19.883Z'
---

## Overview

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

## Affected

- `mipl_grouped_checkout_fields_for_woocommerce._customize_organize_checkout_fields. <= 1.2.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
