CVE-2026-78371

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.

https://wpscan.com/vulnerability/7a9cda53-c62a-4249-baf2-7f25feeed17a/