Sceawere
Vulnerability Detail
CVE-2026-78371UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insecure Direct Object Reference Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- File Uploads Addon for WooCommerce
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-10-05T06:16:58.830Z",
"pubdate": "2026-10-05T06:16:58.830Z",
"executiveSummary": "The File Uploads Addon for WooCommerce plugin, specifically versions prior to 1.7.6, contains a critical Insecure Direct Object Reference (IDOR) vulnerability.\nThis security flaw enables unauthenticated remote attackers to access, download, and potentially exfiltrate sensitive files uploaded by customers to the server.\nThe vulnerability stems from a lack of server-side authorization checks when handling file retrieval requests. By failing to validate the ownership or session context of the requester against the requested file, the application exposes private data to any individual who can determine or guess the resource's filename.\nThe impact is significant, potentially leading to a massive privacy breach, unauthorized data exposure, and potential regulatory non-compliance regarding customer data protection.\nThere are no complex exploitation requirements; the attacker does not need prior authentication or elevated privileges. The threat surface is exposed via the web server, making it reachable by any remote actor capable of performing a standard HTTP GET request.\nRisk implications include the exposure of Personally Identifiable Information (PII) or other sensitive customer data, which may be leveraged for further attacks or identity-related exploitation.",
"technicalDetails": "The vulnerability is rooted in an Insecure Direct Object Reference (IDOR) flaw within the File Uploads Addon for WooCommerce plugin. The plugin fails to implement granular access control mechanisms or ownership validation when a file download request is initiated.\nThe root cause lies in the application logic's failure to verify the session identity or the ownership relationship between the authenticated user who performed the upload and the entity requesting the file retrieval. Consequently, the download endpoint relies solely on the provided file identifier or filename rather than a secure token, session variable, or database-backed access control list (ACL).\nAn attacker can exploit this by crafting a direct HTTP request to the file download endpoint. Since the backend does not perform an authorization check against the user session to ensure the requester is the authorized owner or a privileged administrator, the server processes the request and serves the resource directly from the filesystem or media library.\nAttack flow: 1. An attacker identifies the URL pattern for file downloads within the plugin. 2. The attacker identifies or predicts the naming convention used for uploaded files. 3. The attacker initiates an HTTP GET request to the file download path for a target file. 4. The server receives the request, identifies the file by the provided name, and transmits the file contents to the attacker's client.\nThe vulnerable component is the file handling module within the plugin responsible for processing download requests. This component lacks the necessary logic to bind file access to specific WordPress user IDs or valid session-based permissions.\nThe vulnerability is accessible to unauthenticated attackers, as the endpoint does not require a valid session or active login to authorize the download operation. The network exposure is broad, as the plugin typically exposes this functionality to any entity capable of communicating with the WordPress web server.\nPost-exploitation impact involves the unauthorized disclosure of potentially sensitive customer data stored in the uploaded files. An attacker could automate this process using enumeration scripts to harvest large volumes of user files from the server, resulting in a substantial breach of confidentiality."
}