PatchSiren cyber security CVE debrief
CVE-2026-16777 jkohlbach CVE debrief
The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal. Authenticated attackers with shop manager-level access can read arbitrary files, potentially exposing sensitive information. This vulnerability exists in plugin versions up to 2.8.0 via the 'filename' parameter, allowing attackers to access sensitive data. WordPress administrators and security teams should assess exposure and prioritize patching.
- Vendor
- jkohlbach
- Product
- Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-18
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-18
- Advisory updated
- 2026-09-18
Who should care
WordPress administrators and security teams responsible for maintaining installations with the Store Exporter plugin should assess exposure and prioritize patching. This includes reviewing current plugin versions, evaluating potential impact, and implementing compensating controls if necessary.
Why it matters
CVE-2026-16777 is a Directory Traversal vulnerability in the Store Exporter plugin for WordPress. Authenticated attackers with shop manager-level access can read arbitrary files, potentially exposing sensitive information. WordPress administrators and security teams should assess exposure and prioritize patching.
- Sensitive information disclosure
- Potential data breach through unauthorized file access
- Increased risk of targeted attacks exploiting this vulnerability
Technical summary
The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Defensive priority
Assess exposure and prioritize patching for WordPress installations using the vulnerable plugin version.
Recommended defensive actions
- Patch or update the Store Exporter plugin to a version beyond 2.8.0.
- Restrict access to the plugin's functionality to trusted users only.
- Monitor for suspicious file access attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability exists in plugin versions up to 2.8.0. Authenticated attackers with shop manager-level access can exploit the Directory Traversal vulnerability via the 'filename' parameter. Evidence is based on CVE Program and NVD records, with additional details from security researchers at Wordfence. Defenders should verify affected scope, review official advisories, and monitor for suspicious file access attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16777 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16777
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16777 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16777
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Abstracts/Abstract_Exporter.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Classes/WP_Admin.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.