Sensitive Information Exposure in WooCommerce Order Export Plugin by WebToffee
CVE-2026-94375

5.3MEDIUM

What is CVE-2026-94375?

The Order Export & Order Import for WooCommerce plugin for WordPress is exposed to sensitive information leakage in all versions up to and including 2.7.8. This vulnerability allows unauthorized users to access the exported order CSV files that contain critical customer identifiable information (PII) such as names, addresses, emails, phone numbers, and order details. The flaw arises when default security measures, like .htaccess and index.php, are not present in the wp-content/webtoffee_export/ directory. This issue can occur after actions like uninstalling or reinstalling the plugin, performing migrations, restoring backups, or synchronizing staging sites. The export filenames generated by the plugin follow a predictable timestamp pattern, significantly increasing the risk of brute-force attacks, enabling potential attackers to easily guess and access sensitive files.

Affected Version(s)

Order Export & Order Import for WooCommerce 0 <= 2.7.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Boluwatife Opeyemi (tcyph3r)
.