Sceawere

Vulnerability Detail

CVE-2026-13607UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

File Uploads Addon Unauthorized Access

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
13h ago
Vendor
Unknown
Product
File Uploads Addon for WooCommerce
Attack Type
CWE-284 Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-05T06:16:58.683Z",
  "pubdate": "2026-10-05T06:16:58.683Z",
  "executiveSummary": "The File Uploads Addon for WooCommerce WordPress plugin through version 1.7.6 is susceptible to an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability. The vulnerability stems from the plugin storing customer-uploaded files within a publicly accessible directory on the web server while failing to implement effective access control mechanisms.\nThis flaw allows unauthenticated, remote attackers to retrieve sensitive customer data without needing to interact with the plugin's legitimate authentication-gated download mechanism. By successfully guessing or discovering file naming patterns, an attacker can bypass authorization checks entirely.\nThe impact of this vulnerability is significant, as it exposes potentially sensitive user-uploaded content, including personal identification documents, private records, or proprietary information, to unauthorized parties. This constitutes a severe privacy breach and poses risks of data exfiltration and unauthorized information disclosure.\nSuccessful exploitation requires no prior authentication or administrative privileges, as the files are reachable via standard HTTP GET requests directly to the web-accessible directory. Organizations utilizing affected versions are at high risk of data exposure if attackers identify the upload path and predictable naming conventions.",
  "technicalDetails": "The vulnerability resides in the core file storage logic of the File Uploads Addon for WooCommerce WordPress plugin (up to version 1.7.6). The plugin facilitates file uploads from customers; however, the architectural implementation of these uploads is inherently insecure due to its placement in a directory directly accessible via the web server's document root.\nRoot Cause Analysis: The plugin relies on a custom security mechanism designed to control downloads; however, this mechanism is circumvented because it does not modify the underlying filesystem permissions or implement web server-level access restrictions (such as .htaccess or Nginx configuration directives) to block direct access. The 'security' is enforced only at the application layer, which is ignored when a file is requested directly via its URI, bypassing the plugin's authentication checks.\nAttack Flow and Methodology: 1. Reconnaissance: An attacker identifies that the target site uses the File Uploads Addon for WooCommerce and determines the default directory structure where uploads are stored (e.g., /wp-content/uploads/file-uploads-addon/). 2. Enumeration: If the naming convention of the stored files is predictable (e.g., using sequential identifiers or standard timestamp-based formatting), the attacker can enumerate filenames or perform brute-force guessing against the public URL. 3. Exploitation: The attacker sends an HTTP GET request directly to the guessed path of the uploaded file. Because the web server treats this as a standard static file request, it bypasses the plugin's PHP-based access control logic. 4. Exfiltration: The server responds with the contents of the file, allowing the unauthorized download of sensitive customer data.\nAuthentication and Exposure: This vulnerability does not require authentication or elevated privileges. It is exploitable over the network by any remote, unauthenticated user capable of reaching the web server. The attack is entirely passive from the server-side perspective, as it involves standard file retrieval requests, often evading basic application-level WAF rules that might be configured to monitor only plugin-specific POST/GET parameters.\nPost-Exploitation: Upon gaining access to these files, the attacker can aggregate and exfiltrate the stored data. This represents a complete bypass of the intended access control mechanism, rendering the plugin's native security features ineffective."
}
CVE-2026-13607: File Uploads Addon Unauthorized Access (MEDIUM Severity, CVSS: 5.9) | Sceawere