Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive Information Exposure via Predictable Export File Names
- ID
- WPSEC-2026-0676
- Plugin
- Order Export & Order Import for WooCommerce (order-import-export-for-woocommerce)
- Affected
- from 2.0.0 before 2.7.9
- Remediation
- Update to 2.7.9 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Order Export & Order Import for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8. Generated export files are named only from the export type and a timestamp. The export directory's .htaccess and index.php protection files are only written when the directory is first created. This makes it possible for unauthenticated attackers to guess the URL of export files holding order and customer personal data and download them. Exploitation requires that an export has been generated and that the directory protection is missing or ignored by the web server (for example on Nginx).
References
- https://wpsec.com/vuln/WPSEC-2026-0676/
- https://plugins.svn.wordpress.org/order-import-export-for-woocommerce/tags/2.7.9/
- https://wordpress.org/plugins/order-import-export-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS