WORDPRESS · SEPTEMBER 2026 · EARLY WARNING

MIPL Grouped Checkout Fields for WooCommerce Vulnerability Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields (wordpress)
Patched version
Not yet available
CVE-2026-8778

An early warning has been issued for a critical vulnerability in the MIPL Grouped Checkout Fields for WooCommerce plugin for WordPress. Versions up to and including 1.2.1 are reportedly affected.

What happened

The MIPL Grouped Checkout Fields for WooCommerce plugin for WordPress is under investigation for a critical vulnerability. This vulnerability, tracked as CVE-2026-8778, allows for arbitrary file uploads due to missing file type validation. This may enable unauthenticated attackers to upload arbitrary files on the affected site's server, potentially leading to remote code execution.

Professional software engineers using this plugin should assess their exposure by checking if their installations are running version 1.2.1 or earlier. The vulnerability has a CVSS score of 9.8, indicating its critical severity.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using MIPL Grouped Checkout Fields for WooCommerce version 1.2.1 or earlier, you may be affected.

What should I do right now?

Check your plugin version and consider disabling the plugin if you are using version 1.2.1 or earlier. Monitor updates from the primary sources for a fix.

Is there a patched version available?

No official fix has been published yet. Consult the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats