Sensitive Information Exposure in WooCommerce Order Export Plugin by WebToffee
CVE-2026-94375
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-94375?
The Order Export & Order Import for WooCommerce plugin for WordPress is exposed to sensitive information leakage in all versions up to and including 2.7.8. This vulnerability allows unauthorized users to access the exported order CSV files that contain critical customer identifiable information (PII) such as names, addresses, emails, phone numbers, and order details. The flaw arises when default security measures, like .htaccess and index.php, are not present in the wp-content/webtoffee_export/ directory. This issue can occur after actions like uninstalling or reinstalling the plugin, performing migrations, restoring backups, or synchronizing staging sites. The export filenames generated by the plugin follow a predictable timestamp pattern, significantly increasing the risk of brute-force attacks, enabling potential attackers to easily guess and access sensitive files.
Affected Version(s)
Order Export & Order Import for WooCommerce 0 <= 2.7.8