The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded...
zetlyn/cve-ghsa vulnerability ghsa GHSA-8493-3qrc-44fv cve CVE-2026-13607 known 2026-10-05
https://github.com/advisories/GHSA-8493-3qrc-44fv
Properties
| severity | unknownreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-13607",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.",
"ghsa_id": "GHSA-8493-3qrc-44fv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-8493-3qrc-44fv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-8493-3qrc-44fv"
},
{
"type": "CVE",
"value": "CVE-2026-13607"
}
],
"nvd_published_at": "2026-10-05T06:16:58Z",
"published_at": "2026-10-05T06:30:23Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-13607",
"https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9",
"https://github.com/advisories/GHSA-8493-3qrc-44fv"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded...",
"type": "unreviewed",
"updated_at": "2026-10-05T06:30:30Z",
"url": "https://api.github.com/advisories/GHSA-8493-3qrc-44fv",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|
Text
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded...
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.