CVE-2026-81774: WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
Affected Software
1 affected component
WooCommerce Product Attachment<=2.3.3
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other privileges. The vector is network-accessible and requires no user interaction.
2
What security impact is indicated?
The reported impact is exposure of sensitive data, with high confidentiality impact. Integrity and availability impact are listed as none.
3
Which installations are affected?
WooCommerce Product Attachment versions up to and including 2.3.3 are identified as affected.