CVE-2026-78371
Received Received - Intake

Insecure File Download in WooCommerce File Uploads Addon

Vulnerability report for CVE-2026-78371, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: WPScan

Description

The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
woocommerce file_uploads_addon to 1.7.6 (exc)
woocommerce file_uploads_addon From 1.7.2 (inc) to 1.7.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the File Uploads Addon for WooCommerce WordPress plugin. It allows unauthenticated attackers to download files uploaded by other customers by guessing or knowing the file name. The plugin fails to verify that the requester is the same customer who uploaded the file.

Detection Guidance

To detect this vulnerability, check if your WooCommerce File Uploads Addon plugin version is between 1.7.2 and 1.7.5. You can use WordPress commands like 'wp plugin list' or check the plugin version in the WordPress admin panel.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive customer-uploaded files, potentially exposing private data such as documents or images. Attackers could use this to steal information, violate privacy, or gain insights for further attacks.

Compliance Impact

This vulnerability could result in non-compliance with data protection regulations like GDPR and HIPAA, as it allows unauthorized access to personal or sensitive data. Organizations may face legal penalties, reputational damage, and loss of customer trust.

Mitigation Strategies

Immediately update the File Uploads Addon for WooCommerce plugin to version 1.7.6 or later. This can be done via the WordPress admin panel or using commands like 'wp plugin update woocommerce-file-uploads-addon'.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78371. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart