The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.

cve CVE-2026-13607 2 sources, 2 claims · Watch

NVD writes:
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism. the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsunknown/file_uploads_addon_for_woocommerce
NVD says “Unknown · File Uploads Addon for WooCommerce”
made_byunknown
NVD says “Unknown”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD5.9
receipt
Source
NVD
Its words
5.9
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-05 12:23 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
2026-10-05 12:23 UTC5.9
2026-10-05 06:21 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "File Uploads Addon for WooCommerce",
            "vendor": "Unknown",
            "versions": [
              {
                "lessThanOrEqual": "1.7.6",
                "status": "affected",
                "version": "1.7.2",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "contact@wpscan.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
      }
    ],
    "id": "CVE-2026-13607",
    "lastModified": "2026-10-05T11:16:47.173",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-13607",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-05T10:49:43.848180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-05T06:16:58.683",
    "references": [
      {
        "source": "contact@wpscan.com",
        "url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
      }
    ],
    "sourceIdentifier": "contact@wpscan.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDFile Uploads Addon for WooCommerce
receipt
Source
NVD
Its words
File Uploads Addon for WooCommerce
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-05 06:21 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "File Uploads Addon for WooCommerce",
            "vendor": "Unknown",
            "versions": [
              {
                "lessThanOrEqual": "1.7.6",
                "status": "affected",
                "version": "1.7.2",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "contact@wpscan.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
      }
    ],
    "id": "CVE-2026-13607",
    "lastModified": "2026-10-05T11:16:47.173",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-13607",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-05T10:49:43.848180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-05T06:16:58.683",
    "references": [
      {
        "source": "contact@wpscan.com",
        "url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
      }
    ],
    "sourceIdentifier": "contact@wpscan.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
GitHub advisoriesunknown
receipt
Source
GitHub advisories
Its words
unknown
Read by
field:severity
Said since
2026-10-05 12:20 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-13607",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [],
  "description": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.",
  "ghsa_id": "GHSA-8493-3qrc-44fv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-8493-3qrc-44fv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-8493-3qrc-44fv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-13607"
    }
  ],
  "nvd_published_at": "2026-10-05T06:16:58Z",
  "published_at": "2026-10-05T06:30:23Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-13607",
    "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9",
    "https://github.com/advisories/GHSA-8493-3qrc-44fv"
  ],
  "repository_advisory_url": null,
  "severity": "unknown",
  "source_code_location": "",
  "summary": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded...",
  "type": "unreviewed",
  "updated_at": "2026-10-05T06:30:30Z",
  "url": "https://api.github.com/advisories/GHSA-8493-3qrc-44fv",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Status
status
NVDReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-10-05 06:21 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "File Uploads Addon for WooCommerce",
            "vendor": "Unknown",
            "versions": [
              {
                "lessThanOrEqual": "1.7.6",
                "status": "affected",
                "version": "1.7.2",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "contact@wpscan.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
      }
    ],
    "id": "CVE-2026-13607",
    "lastModified": "2026-10-05T11:16:47.173",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-13607",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-05T10:49:43.848180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-05T06:16:58.683",
    "references": [
      {
        "source": "contact@wpscan.com",
        "url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
      }
    ],
    "sourceIdentifier": "contact@wpscan.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDUnknown
receipt
Source
NVD
Its words
Unknown
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-05 06:21 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unknown",
            "product": "File Uploads Addon for WooCommerce",
            "vendor": "Unknown",
            "versions": [
              {
                "lessThanOrEqual": "1.7.6",
                "status": "affected",
                "version": "1.7.2",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "contact@wpscan.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
      }
    ],
    "id": "CVE-2026-13607",
    "lastModified": "2026-10-05T11:16:47.173",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-13607",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-05T10:49:43.848180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-05T06:16:58.683",
    "references": [
      {
        "source": "contact@wpscan.com",
        "url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
      }
    ],
    "sourceIdentifier": "contact@wpscan.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.
zetlyn/cve-nvd · 2026-10-05
cvss 5.9 product File Uploads Addon for WooCommerce status Received vendor Unknown source
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded...
zetlyn/cve-ghsa · 2026-10-05
severity unknown source