CVE-2026-16777: Store Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' Parameter
The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers (WordPress plugin)to a version that resolves this vulnerability.Fixed in 2.8.0 - Compensating control
Ensure only trusted users have Shop Manager+ (authenticated) access so the vulnerable 'filename' parameter cannot be exploited for directory traversal.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to WordPress with shop manager-level access or higher. Unauthenticated visitors and lower-privileged accounts are not identified as able to exploit it.
Which installations are affected?
All versions of the Store Exporter plugin up to and including 2.8.0 are affected. The provided information does not state whether any configuration changes are required for exploitation.
What could an attacker access?
A qualifying attacker can use the filename parameter for directory traversal to read arbitrary files on the server. Those files may contain sensitive information.