Directory Traversal Vulnerability in Direct Download for WooCommerce Plugin by WordPress
CVE-2026-15019
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-15019?
The Direct Download for WooCommerce plugin for WordPress is susceptible to a Directory Traversal vulnerability across all versions up to and including 1.19. This flaw arises from improper input validation in the top-level include function, allowing unauthenticated attackers to potentially read sensitive contents of arbitrary files on the server. The product ownership verification process only checks for the existence of free virtual downloadable products, failing to ensure that the requested file path corresponds to the specified product downloads. Consequently, this vulnerability can be exploited on any WooCommerce site with at least one such product, posing a significant risk to sensitive data exposure.
Affected Version(s)
Direct Download for WooCommerce 0 <= 1.19