File Upload Vulnerability in WooCommerce Plugin by WordPress
CVE-2026-13607

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-13607?

The File Uploads Addon for WooCommerce, Version 1.7.6, poses a risk by allowing customer-uploaded files to be stored in a publicly accessible uploads directory. The addon attempts to restrict access to these files; however, this restriction is not effectively enforced. Consequently, an unauthenticated attacker who is aware of or can guess the name of a file can directly access these files, bypassing the intended security measures of the addon. This vulnerability raises significant concerns regarding the confidentiality of customer data and highlights the importance of implementing robust access controls for uploaded content.

Affected Version(s)

File Uploads Addon for WooCommerce 1.7.2 <= 1.7.6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

J4ck13Ch4n
WPScan
.