WooCommerce 的 File Uploads 附加插件(版本通过 1.7.6)将用户上传的文件存储在一个公开可访问的 Web 目录中,其生成的访问控制机制无效。因此,任何未认证的攻击者只要知晓或猜测到某个文件的名称,便可直接获取用户已上传的文件,从而绕过该插件在 1.7.6 及之前版本中所设置的认证下载机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | File Uploads Addon for WooCommerce | 1.7.2 ~ 1.7.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78371 | File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File | |
| CVE-2026-84169 | UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery |
No comments yet