File Upload Vulnerability in WooCommerce Plugin by WordPress
CVE-2026-13607
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-13607?
The File Uploads Addon for WooCommerce, Version 1.7.6, poses a risk by allowing customer-uploaded files to be stored in a publicly accessible uploads directory. The addon attempts to restrict access to these files; however, this restriction is not effectively enforced. Consequently, an unauthenticated attacker who is aware of or can guess the name of a file can directly access these files, bypassing the intended security measures of the addon. This vulnerability raises significant concerns regarding the confidentiality of customer data and highlights the importance of implementing robust access controls for uploaded content.
Affected Version(s)
File Uploads Addon for WooCommerce 1.7.2 <= 1.7.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.