Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive Information Exposure via Predictable Export File Names

Medium 5.9 CWE-200Fixed in 2.7.9
ID
WPSEC-2026-0676
Plugin
Order Export & Order Import for WooCommerce (order-import-export-for-woocommerce)
Affected
from 2.0.0 before 2.7.9
Remediation
Update to 2.7.9 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Order Export & Order Import for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8. Generated export files are named only from the export type and a timestamp. The export directory's .htaccess and index.php protection files are only written when the directory is first created. This makes it possible for unauthenticated attackers to guess the URL of export files holding order and customer personal data and download them. Exploitation requires that an export has been generated and that the directory protection is missing or ignored by the web server (for example on Nginx).

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0