The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.
cve CVE-2026-13607 2 sources, 2 claims · Watch
NVD writes:
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism. the claim
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism. the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | unknown/file_uploads_addon_for_woocommerceNVD says “Unknown · File Uploads Addon for WooCommerce” |
| made_by | unknownNVD says “Unknown” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss | NVD | 5.9receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "File Uploads Addon for WooCommerce",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "1.7.6",
"status": "affected",
"version": "1.7.2",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
}
],
"id": "CVE-2026-13607",
"lastModified": "2026-10-05T11:16:47.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-13607",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:49:43.848180Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-05T06:16:58.683",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-284"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | File Uploads Addon for WooCommercereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "File Uploads Addon for WooCommerce",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "1.7.6",
"status": "affected",
"version": "1.7.2",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
}
],
"id": "CVE-2026-13607",
"lastModified": "2026-10-05T11:16:47.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-13607",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:49:43.848180Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-05T06:16:58.683",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-284"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | GitHub advisories | unknownreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-13607",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [],
"description": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.",
"ghsa_id": "GHSA-8493-3qrc-44fv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-8493-3qrc-44fv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-8493-3qrc-44fv"
},
{
"type": "CVE",
"value": "CVE-2026-13607"
}
],
"nvd_published_at": "2026-10-05T06:16:58Z",
"published_at": "2026-10-05T06:30:23Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-13607",
"https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9",
"https://github.com/advisories/GHSA-8493-3qrc-44fv"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded...",
"type": "unreviewed",
"updated_at": "2026-10-05T06:30:30Z",
"url": "https://api.github.com/advisories/GHSA-8493-3qrc-44fv",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "File Uploads Addon for WooCommerce",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "1.7.6",
"status": "affected",
"version": "1.7.2",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
}
],
"id": "CVE-2026-13607",
"lastModified": "2026-10-05T11:16:47.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-13607",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:49:43.848180Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-05T06:16:58.683",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-284"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Unknownreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unknown",
"product": "File Uploads Addon for WooCommerce",
"vendor": "Unknown",
"versions": [
{
"lessThanOrEqual": "1.7.6",
"status": "affected",
"version": "1.7.2",
"versionType": "semver"
}
]
}
],
"source": "contact@wpscan.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism."
}
],
"id": "CVE-2026-13607",
"lastModified": "2026-10-05T11:16:47.173",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-13607",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-05T10:49:43.848180Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-05T06:16:58.683",
"references": [
{
"source": "contact@wpscan.com",
"url": "https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/"
}
],
"sourceIdentifier": "contact@wpscan.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-284"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism. zetlyn/cve-nvd · 2026-10-05 | cvss 5.9 product File Uploads Addon for WooCommerce status Received vendor Unknown | source |
| The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded... zetlyn/cve-ghsa · 2026-10-05 | severity unknown | source |