Sensitive Data Exposure in WooCommerce Product Attachment Plugin
CVE-2026-81774

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81774?

An exploitable vulnerability has been identified in the WooCommerce Product Attachment plugin versions up to 2.3.3, which allows unauthenticated users to access sensitive data. This exposure could potentially lead to unauthorized access to private user information, making it crucial for site owners to update to the latest version to mitigate risks. Ensuring regular updates and monitoring user privileges is essential for maintaining the security integrity of WordPress sites utilizing this plugin.

Affected Version(s)

WooCommerce Product Attachment <= 2.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.