CVE-2026-94375
Received Received - Intake

Sensitive Information Exposure in Order Export & Order Import for WooCommerce

Vulnerability report for CVE-2026-94375, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII β€” including names, billing and shipping addresses, email addresses, phone numbers, and order contents β€” directly over HTTP with no authentication. This is exploitable whenever the .htaccess and index.php guard files are absent from wp-content/webtoffee_export/, which can occur after any uninstall/reinstall cycle, migration, backup restore, or staging sync, since the export directory persists but its guard files do not; export filenames follow a fully deterministic second-precision timestamp pattern, making them brute-forceable across any suspected export window.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
webtoffee Order Export & Order Import for WooCommerce 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Order Export & Order Import for WooCommerce plugin allows unauthenticated attackers to access sensitive customer data like names, addresses, emails, phone numbers, and order details through exposed CSV export files. The issue occurs when guard files are missing from the export directory, which can happen after updates or migrations. Export filenames follow a predictable timestamp pattern, making them easy to guess.

Detection Guidance

Check if the directory wp-content/webtoffee_export/ exists and is accessible without authentication. Look for exported CSV files with timestamps in their filenames. Verify if .htaccess and index.php guard files are missing from this directory.

Impact Analysis

If exploited, attackers could steal customer personally identifiable information (PII) without needing authentication. This could lead to privacy breaches, identity theft, or fraud. Businesses may face reputational damage, customer loss, and potential legal consequences depending on data protection laws.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and potential failure to implement adequate security measures. For HIPAA, if the exposed data includes protected health information, it would also be a serious compliance failure. Organizations could face fines, audits, or mandatory breach notifications.

Mitigation Strategies

Update the plugin to the latest version. Ensure wp-content/webtoffee_export/ has proper .htaccess and index.php guard files. Restrict directory access via server configuration. Remove any exposed CSV files containing sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94375. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart