# CVE-2026-103889 : Vulnérabilités critiques dans des plugins et thèmes WordPress touchant PHP, injection d’objets PHP, exécution distante de code et authentification bypass

> Sur plusieurs plugins et thèmes WordPress, des vulnérabilités critiques (RCE, injection PHP d’objets, bypass d’authentification, et délétion arbitraire de fichiers) permettent à des attaquants non authentifiés ou disposant d’un niveau…

- Page canonique : https://kreomnisvigie.com/cve/cve-2026-103889-wordpress-ecosystem
- Sévérité : Critique · CVSS 9.8 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CISA KEV (exploitation observée) : non
- Éditeur : WordPress ecosystem
- Produits : WordPress + plugins WordPress PHP
- Correctif disponible : non · PoC public : non · Exploitée : non
- Publiée le 11 octobre 2026 · Kreomnis Vigie
- Issue du bulletin du 11 octobre 2026 (10 octobre 2026)
- Mots clés : wordpress-ecosystem, authentification-bypass-bug, arbitrary-file-upload, remote-code-execution, authentication-bypass, unauthenticated-php-object

## Action recommandée

Mettre à jour immédiatement les plugins et thèmes WordPress affectés vers les dernières versions sûres ou appliquer les correctifs fournis par les éditeurs; vérifier les journaux et restaurer les fichiers si nécessaire

## 18 CVE dans cet advisory

- CVE-2026-104732 (WordPress - Advanced IP Blocker) · CVSS 9.8 : authentification bypass (bug de gestion des sessions et nonces)
- CVE-2026-94589 (WordPress - Extensions For CF7) · CVSS 9.8 : Arbitrary File Upload
- CVE-2026-103889 (WooCommerce - 3D Product configurator) · CVSS 9.8 : Remote Code Execution
- CVE-2026-104803 (WPCOM Member) · CVSS 9.8 : Authentication Bypass
- CVE-2026-81797 (Buzz Stone Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-78529 (Alliance Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-66563 (Windsor Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-78535 (Photolia Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-78531 (Jacqueline Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-66567 (Anesta Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-66569 (Kicker Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-66483 (Education Center Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-66482 (Drone Media Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-62125 (Asia Garden Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-62120 (Law Office Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-62124 (N7 - Golf Club Sports & Events Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-62090 (WineShop Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection
- CVE-2026-62123 (Invetex Theme) · CVSS 9.8 : Unauthenticated PHP Object Injection

## Le contexte

Sur plusieurs plugins et thèmes WordPress, des vulnérabilités critiques (RCE, injection PHP d’objets, bypass d’authentification, et délétion arbitraire de fichiers) permettent à des attaquants non authentifiés ou disposant d’un niveau faible d’obtenir un contrôle étendu du serveur ou d’exécuter du code à distance. Les CVE listées ci-dessous démontrent une exposition massive dans l’écosystème WordPress côté web.

## Vecteur d'attaque

surface web, requêtes HTTP/POST sur endpoints vulnérables, absence ou échec de contrôles d’authentification et de validation des entrées

## Systèmes impactés

| Produit | Versions affectées | Versions corrigées |
| --- | --- | --- |
| WordPress + plugins WordPress PHP | Advanced IP Blocker (WordPress) ; Extensions For CF7 (WordPress) ; 3D Product configurator for WooCommerce ; WPCOM Member (WordPress) ; Buzz Stone \| Magazine & Viral Blog WordPress Theme ; Alliance Theme ; Windsor Theme ; Photolia Theme ; Jacqueline Theme ; Anesta Theme ; Kicker Theme ; ShiftCV Theme ; FC United Theme ; Qwery Theme ; Education Center Theme ; Original Theme ; Drone Media Theme ; Asia Garden Theme ; Law Office Theme ; N7 \| Golf Club Sports & Events Theme ; WineShop Theme ; Splendour Theme ; Tipsy Theme ; Stargaze Theme ;  Booster for WooCommerce (plugin) ; CleanSkin Theme ; Dynamic User Directory ; Payever - WooCommerce Gateway ; PPOM – Product Addons & Custom Fields for WooCommerce ; LifterLMS (WP LMS) ; Blocksy Companion (WP) | non communiquée |

Non affecté : voir l'avis de l'éditeur

Statut du correctif : voir l'avis de l'éditeur

## Les vulnérabilités

### CVE-2026-103889 : Remote Code Execution

WooCommerce - 3D Product configurator · CVSS 9.8

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution...

Impact : exécution de code arbitraire sur le serveur via paramètre xpv_image

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-104732 : authentification bypass (bug de gestion des sessions et nonces)

WordPress - Advanced IP Blocker · CVSS 9.8

The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass... (résumé factuel disponible dans l’avis GitHub)

Impact : description technique: bypass d’authentification permettant à un attaquant non authentifié d’exécuter des actions réservées

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-104803 : Authentication Bypass

WPCOM Member · CVSS 9.8

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass...

Impact : bypass d’authentification via session nonce/OAuth state insuffisant

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-62090 : Unauthenticated PHP Object Injection

WineShop Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Wine Shop \<= 3.20 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-62120 : Unauthenticated PHP Object Injection

Law Office Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Law Office \<= 3.20 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-62123 : Unauthenticated PHP Object Injection

Invetex Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Invetex \<= 2.18 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-62124 : Unauthenticated PHP Object Injection

N7 - Golf Club Sports & Events Theme · CVSS 9.8

Unauthenticated PHP Object Injection in N7 | Golf Club Sports & Events \<= 2.21 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-62125 : Unauthenticated PHP Object Injection

Asia Garden Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Asia Garden \<= 1.3.1 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-66482 : Unauthenticated PHP Object Injection

Drone Media Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Drone Media \<= 2.2.0 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-66483 : Unauthenticated PHP Object Injection

Education Center Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Education Center \<= 3.6.12 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-66563 : Unauthenticated PHP Object Injection

Windsor Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Windsor \<= 2.10 versions.

Impact : exécution d’objet PHP injecté via injection non authentifiée

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-66567 : Unauthenticated PHP Object Injection

Anesta Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Anesta \<= 1.5.3 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-66569 : Unauthenticated PHP Object Injection

Kicker Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Kicker \<= 2.2.1 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-78529 : Unauthenticated PHP Object Injection

Alliance Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Alliance \<= 3.11 versions.

Impact : exécution d’objet PHP manipulé

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-78531 : Unauthenticated PHP Object Injection

Jacqueline Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Jacqueline \<= 2.22 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-78535 : Unauthenticated PHP Object Injection

Photolia Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Photolia \<= 1.0.3 versions.

Impact : exécution d’objet PHP injecté

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-81797 : Unauthenticated PHP Object Injection

Buzz Stone Theme · CVSS 9.8

Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme...

Impact : Object injection permettant contrôle serveur

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

### CVE-2026-94589 : Arbitrary File Upload

WordPress - Extensions For CF7 · CVSS 9.8

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload...

Impact : attaque possible d’upload de fichiers exécutables dans le répertoire d’upload

`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`

## Recommandations

- Mettre à jour vers les versions non vulnérables des plugins et thèmes WordPress référencés dès que disponibles.
- Effectuer une revue des journaux d’accès et d’erreurs et surveiller les tentatives d’exploitation sensibles.
- Mener un inventaire des plugins et thèmes actifs et désactiver ceux qui ne sont pas nécessaires ou maintenus.

## Ce qu'il faut retenir

Mettre à jour immédiatement les plugins et thèmes WordPress affectés vers les dernières versions sûres ou appliquer les correctifs fournis par les éditeurs; vérifier les journaux et restaurer les fichiers si nécessaire

Analyse issue du bulletin de veille Kreomnis du 11 octobre 2026 (fenêtre : 10 octobre 2026). Sources croisées listées ci-dessous.

- Kreomnis Vigie

## Références

- [GitHub Advisory – WordPress plugins](https://github.com/advisories) (vendor)
- [NVD – Vulnérabilités associées](https://nvd.nist.gov/vuln/search) (nvd)
- [CVE-2026-104732 : source primaire](https://github.com/advisories/GHSA-pw6h-rjh8-7grw) (nvd)
- [CVE-2026-94589 : source primaire](https://github.com/advisories/GHSA-fjhx-3cm7-whvf) (nvd)
- [CVE-2026-103889 : source primaire](https://github.com/advisories/GHSA-m7vx-2p8f-r357) (nvd)
- [CVE-2026-104803 : source primaire](https://github.com/advisories/GHSA-gj32-ffvm-frj6) (nvd)
- [CVE-2026-81797 : source primaire](https://github.com/advisories/GHSA-jgqp-7548-mqg8) (nvd)
- [CVE-2026-78529 : source primaire](https://github.com/advisories/GHSA-hj6g-q8vx-x324) (nvd)
- [CVE-2026-66563 : source primaire](https://github.com/advisories/GHSA-vfx8-984f-hxhg) (nvd)
- [CVE-2026-78535 : source primaire](https://github.com/advisories/GHSA-rfhw-cf7w-cjpq) (nvd)
- [CVE-2026-78531 : source primaire](https://github.com/advisories/GHSA-5568-p4h7-h6jx) (nvd)
- [CVE-2026-66567 : source primaire](https://github.com/advisories/GHSA-xm2p-xf7g-7qxp) (nvd)
- [CVE-2026-66569 : source primaire](https://github.com/advisories/GHSA-67gf-mq47-63m5) (nvd)
- [CVE-2026-66483 : source primaire](https://github.com/advisories/GHSA-4mc9-h8qv-hj9w) (nvd)
- [CVE-2026-66482 : source primaire](https://github.com/advisories/GHSA-rg79-c57x-j75x) (nvd)
- [CVE-2026-62125 : source primaire](https://github.com/advisories/GHSA-gfr5-mr4f-j8gp) (nvd)
- [CVE-2026-62120 : source primaire](https://github.com/advisories/GHSA-5mqj-g4vh-q3mp) (nvd)
- [CVE-2026-62124 : source primaire](https://github.com/advisories/GHSA-pf73-6px2-cj3r) (nvd)
- [CVE-2026-62090 : source primaire](https://github.com/advisories/GHSA-pmpg-93xx-xvrg) (nvd)
- [CVE-2026-62123 : source primaire](https://github.com/advisories/GHSA-mjr4-xvvg-63x3) (nvd)

Source : Kreomnis Vigie, https://kreomnisvigie.com/cve/cve-2026-103889-wordpress-ecosystem. Analyse à usage défensif uniquement.
