{
 "id": "WPSEC-2026-0676",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0676/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0676/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0676/index.md",
 "title": "Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive Information Exposure via Predictable Export File Names",
 "description": "The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8. Generated export files are named only from the export type and a timestamp. The export directory's .htaccess and index.php protection files are only written when the directory is first created. This makes it possible for unauthenticated attackers to guess the URL of export files holding order and customer personal data and download them. Exploitation requires that an export has been generated and that the directory protection is missing or ignored by the web server (for example on Nginx).",
 "plugin": {
  "slug": "order-import-export-for-woocommerce",
  "name": "Order Export & Order Import for WooCommerce",
  "full_name": "Order Export & Order Import for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/order-import-export-for-woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/order-import-export-for-woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/order-import-export-for-woocommerce"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.0.0",
    "from_inclusive": true,
    "to": "2.7.9",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.0.0 before 2.7.9"
  ]
 },
 "introduced_in": "2.0.0",
 "fixed_in": "2.7.9",
 "remediation": "Update to 2.7.9 or later.",
 "fix_released": "2026-10-07T19:39:58+00:00",
 "published": "2026-10-08T19:40:50+00:00",
 "updated": "2026-10-08T07:41:05.867409+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0676/",
  "https://plugins.svn.wordpress.org/order-import-export-for-woocommerce/tags/2.7.9/",
  "https://wordpress.org/plugins/order-import-export-for-woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/order-import-export-for-woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}