Unrated severityNVD Advisory· Published Oct 5, 2026
CVE-2026-78371
CVE-2026-78371
Description
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.7.6
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.