CVE-2026-15019: Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment

Published Sep 10, 2026
·
Updated

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloadable product exists on the site — not that the requested file path belongs to that product's configured downloads — making exploitation viable on any WooCommerce site with at least one such product.

Affected Software

1 affected component
WooCommerce Direct Download for WooCommerce<=1.19

Event History

Sep 10, 2026
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are realistically exposed to exploitation?

Any site running Direct Download for WooCommerce version 1.19 or earlier is exposed if it has at least one WooCommerce product that is free, virtual, and downloadable. The requested file does not need to be one of that product's configured downloads.

2

Does exploitation require an authenticated WordPress or WooCommerce account?

No. The vulnerability can be exploited by an unauthenticated attacker over the network, with no user interaction required.

3

What could an attacker obtain through this issue?

An attacker can read arbitrary files on the server through directory traversal. Files accessible to the affected application may contain sensitive information.

4

How can I determine whether the site meets the stated exploitation condition?

Check whether the affected plugin is installed at version 1.19 or earlier, then review WooCommerce products for at least one product configured as free, virtual, and downloadable. If both conditions are present, the described product ownership check can be satisfied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203