CVE-2026-13607: File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.
Affected Software
Event History
Frequently Asked Questions
Who can access exposed uploaded files?
Any unauthenticated remote attacker can retrieve a customer-uploaded file if they know or can guess its filename. No WordPress or WooCommerce account is required.
What conditions are required for exploitation?
The site must use the affected plugin version through 1.7.6 and have customer-uploaded files stored in the publicly web-accessible uploads directory. The attacker needs the name of a target file, either by knowing it or successfully guessing it.
How can I determine whether files may already be exposed?
Review customer-uploaded files handled by the plugin and determine whether they are stored under a web-accessible uploads directory. Test whether a file can be retrieved directly by its URL without authentication rather than through the plugin's authenticated download mechanism.