PatchSiren cyber security CVE debrief
CVE-2026-78371 ThemeComplete CVE debrief
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. This vulnerability impacts confidentiality and could lead to data breaches if exploited. Defenders managing WooCommerce installations with the File Uploads Addon should assess exposure and prioritize verification of their installations.
- Vendor
- ThemeComplete
- Product
- File Uploads Addon for WooCommerce
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders managing WooCommerce installations with the File Uploads Addon should assess exposure and prioritize verification of their installations. This includes reviewing current configurations, updating to the latest version if necessary, and implementing additional security measures to protect against potential exploitation.
Why it matters
CVE-2026-78371 allows unauthenticated attackers to download other customers' uploaded files if they know or guess the file names, impacting confidentiality and potentially leading to data breaches.
- Potential unauthorized access to sensitive customer files
- Possible data breaches due to insecure file handling
- Need for verification of WooCommerce File Uploads Addon installations and configurations
Technical summary
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. This vulnerability is a result of inadequate access control and could be exploited for unauthorized file downloads, potentially leading to data breaches. Defenders should prioritize verifying exposure of WooCommerce File Uploads Addon installations and restrict access to uploaded files.
Defensive priority
Defenders should prioritize verifying exposure of WooCommerce File Uploads Addon installations and restrict access to uploaded files.
Recommended defensive actions
- Verify WooCommerce File Uploads Addon version and restrict access to uploaded files
- Implement additional monitoring for suspicious file access requests
- Review and update incident response plans for potential data breaches
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE description and source reference indicate that the plugin does not verify file access requests, allowing potential unauthorized file downloads. The vulnerability has been publicly disclosed and may be targeted by attackers. Defenders should verify the exposure of WooCommerce File Uploads Addon installations and restrict access to uploaded files.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78371 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78371
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78371 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78371
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/7a9cda53-c62a-4249-baf2-7f25feeed17a/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.