Sceawere
Vulnerability Detail
CVE-2026-94375UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Sensitive Information Disclosure via get_file_path
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 2h ago
- Vendor
- webtoffee
- Product
- Order Export & Order Import for WooCommerce
- Attack Type
- CWE-552 Files or Directories Accessible to External Parties
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is exploitable whenever the .htaccess and index.php guard files are absent from wp-content/webtoffee_export/, which can occur after any uninstall/reinstall cycle, migration, backup restore, or staging sync, since the export directory persists but its guard files do not; export filenames follow a fully deterministic second-precision timestamp pattern, making them brute-forceable across any suspected export window.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-10T06:16:44.857Z",
"pubdate": "2026-10-10T06:16:44.857Z",
"executiveSummary": "The Order Export & Order Import for WooCommerce plugin for WordPress is susceptible to an unauthenticated sensitive information exposure vulnerability. This flaw resides within the get_file_path function, which fails to enforce access control mechanisms when retrieving exported order CSV files.\nThe vulnerability allows unauthorized remote attackers to retrieve sensitive customer Personal Identifiable Information (PII), such as full names, billing/shipping addresses, email addresses, phone numbers, and detailed order contents. The risk is significantly elevated due to the deterministic, timestamp-based naming convention used for export files.\nExploitation is feasible in environments where the protective .htaccess and index.php guard files are absent from the /wp-content/webtoffee_export/ directory. This state is frequently encountered following plugin uninstallation, system migration, site restoration, or staging environment synchronization, as these administrative files are often not restored or recreated correctly.\nSuccessful exploitation requires no prior authentication or administrative privileges. Given the predictable file-naming pattern, an attacker can conduct brute-force enumeration of the export directory to identify and download sensitive datasets, leading to a complete compromise of customer data confidentiality.",
"technicalDetails": "The vulnerability stems from improper input validation and an absence of authorization checks within the get_file_path logic of the Order Export & Order Import for WooCommerce plugin. The plugin facilitates order data exports, storing the generated CSV files within the /wp-content/webtoffee_export/ directory.\nUnder secure configurations, the plugin attempts to protect this directory via index.php and .htaccess files to prevent direct file access over HTTP. However, these security controls are fragile; they are often purged or omitted during routine maintenance, such as site migrations, backup restoration, or staging syncs. Because the /wp-content/webtoffee_export/ directory itself persists across these events while the guard files do not, the directory becomes publicly accessible via the web server.\nThe exploitation process is highly efficient due to the deterministic naming schema. Files are generated using a second-precision timestamp, which is highly predictable. An attacker can map the expected export window based on the site's activity or general business hours. Once the window is identified, the attacker initiates a brute-force enumeration of possible file paths against the web server.\nThe attack flow proceeds as follows: 1) The attacker identifies that the /wp-content/webtoffee_export/ directory lacks protective guard files. 2) The attacker leverages the deterministic timestamp pattern to construct potential file URLs. 3) The attacker sends unauthenticated HTTP GET requests to the constructed paths. 4) If the file exists, the web server serves the CSV file directly to the attacker, bypassing the WordPress application layer and any internal authorization checks. 5) The attacker captures the exported CSV, obtaining full access to PII and order metadata.\nThis vulnerability affects all versions of the plugin up to and including 2.7.8. The impact is severe, as it facilitates unauthorized mass data exfiltration of customer records. Since the vulnerability resides at the file system level and bypasses the PHP application execution flow entirely, standard authentication or session-based security controls are ineffective once the directory is reachable. The reliance on obscurity—the presumed secrecy of the timestamped filename—is insufficient, as the low entropy of the filename structure allows for rapid automated enumeration."
}