PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16777 jkohlbach CVE debrief

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal. Authenticated attackers with shop manager-level access can read arbitrary files, potentially exposing sensitive information. This vulnerability exists in plugin versions up to 2.8.0 via the 'filename' parameter, allowing attackers to access sensitive data. WordPress administrators and security teams should assess exposure and prioritize patching.

Vendor
jkohlbach
Product
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-09-18
Advisory published
2026-09-18
Advisory updated
2026-09-18

Who should care

WordPress administrators and security teams responsible for maintaining installations with the Store Exporter plugin should assess exposure and prioritize patching. This includes reviewing current plugin versions, evaluating potential impact, and implementing compensating controls if necessary.

Why it matters

CVE-2026-16777 is a Directory Traversal vulnerability in the Store Exporter plugin for WordPress. Authenticated attackers with shop manager-level access can read arbitrary files, potentially exposing sensitive information. WordPress administrators and security teams should assess exposure and prioritize patching.

  • Sensitive information disclosure
  • Potential data breach through unauthorized file access
  • Increased risk of targeted attacks exploiting this vulnerability

Technical summary

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Defensive priority

Assess exposure and prioritize patching for WordPress installations using the vulnerable plugin version.

Recommended defensive actions

  • Patch or update the Store Exporter plugin to a version beyond 2.8.0.
  • Restrict access to the plugin's functionality to trusted users only.
  • Monitor for suspicious file access attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability exists in plugin versions up to 2.8.0. Authenticated attackers with shop manager-level access can exploit the Directory Traversal vulnerability via the 'filename' parameter. Evidence is based on CVE Program and NVD records, with additional details from security researchers at Wordfence. Defenders should verify affected scope, review official advisories, and monitor for suspicious file access attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16777 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16777

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16777 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16777

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Abstracts/Abstract_Exporter.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Classes/WP_Admin.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.