CVE-2026-78371: File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File Disclosure
Published Oct 5, 2026
·Updated
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.
Affected Software
1 affected component
WooCommerce File Uploads Addon for WooCommerce<1.7.6
Event History
Oct 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using the File Uploads Addon for WooCommerce plugin before version 1.7.6 are affected if customers upload files through the plugin.
2
What does an attacker need to exploit it?
An attacker does not need to authenticate, but must know or successfully guess the name of a customer-uploaded file.
3
What information could be exposed?
Other customers' files uploaded through the affected plugin may be downloaded by an unauthenticated requester.
4
How can I remediate the issue?
Update the plugin to version 1.7.6 or later.