Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is exploitable whenever the .htaccess and index.php guard files are absent from wp-content/webtoffee_export/, which can occur after any uninstall/reinstall cycle, migration, backup restore, or staging sync, since the export directory persists but its guard files do not; export filenames follow a fully deterministic second-precision timestamp pattern, making them brute-forceable across any suspected export window. | |
| Title | Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive File Exposure via Missing Directory Guard Re-verification in get_file_path() | |
| Weaknesses | CWE-552 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-10T05:31:00.396Z
Reserved: 2026-09-21T12:26:37.453Z
Link: CVE-2026-94375
No data.
Status : Received
Published: 2026-10-10T06:16:44.857
Modified: 2026-10-10T06:16:44.857
Link: CVE-2026-94375
No data.
OpenCVE Enrichment
No data.
-
CWE-552
Files or Directories Accessible to External Parties