# Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive Information Exposure via Predictable Export File Names

- **ID:** WPSEC-2026-0676
- **Plugin:** Order Export & Order Import for WooCommerce (`order-import-export-for-woocommerce`), https://wordpress.org/plugins/order-import-export-for-woocommerce/
- **Affected versions:** from 2.0.0 before 2.7.9
- **Fixed in:** 2.7.9 (Update to 2.7.9 or later.)
- **Severity:** Medium 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/order-import-export-for-woocommerce
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0676/

## Description

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8. Generated export files are named only from the export type and a timestamp. The export directory's .htaccess and index.php protection files are only written when the directory is first created. This makes it possible for unauthenticated attackers to guess the URL of export files holding order and customer personal data and download them. Exploitation requires that an export has been generated and that the directory protection is missing or ignored by the web server (for example on Nginx).

## References

- https://wpsec.com/vuln/WPSEC-2026-0676/
- https://plugins.svn.wordpress.org/order-import-export-for-woocommerce/tags/2.7.9/
- https://wordpress.org/plugins/order-import-export-for-woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0676/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
