---
id: CVE-2026-13607
title: >-
  The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores
  customer-uploaded files in a publicly web-accessible uploads directory and the
  access restriction it generates is ineffective, so an unauthenticated attacker
  wh…
summary: >-
  The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores
  customer-uploaded files in a publicly web-accessible uploads directory and the
  access restriction it generates is ineffective, so an unauthenticated attacker
  wh…
severity: none
cwe:
  - CWE-284
product: File Uploads Addon for WooCommerce
affected:
  - file_uploads_addon_for_woocommerce >= 1.7.2 <= 1.7.6
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T06:16:58.683'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13607'
references:
  - url: 'https://wpscan.com/vulnerability/6eb71c2f-5060-42ed-9a8f-c7ade01e32a9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T06:13:49.197Z'
---

## Overview

The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly, bypassing the File Uploads Addon for WooCommerce WordPress plugin through 1.7.6's authenticated download mechanism.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
