---
id: CVE-2026-16777
title: >-
  The Store Exporter – Export WooCommerce Products, Orders, Subscriptions,
  Customers plugin for WordPress is vulnerable to Directory Traversal in all
  versions up to, and including, 2.8.0 via the 'filename' parameter parameter
summary: >-
  The Store Exporter – Export WooCommerce Products, Orders, Subscriptions,
  Customers plugin for WordPress is vulnerable to Directory Traversal in all
  versions up to, and including, 2.8.0 via the 'filename' parameter parameter.
  This makes i…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: jkohlbach
product: 'Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers'
affected:
  - >-
    store_exporter_export_woocommerce_products_orders_subscriptions_customers <=
    2.8.0
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:09.413'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16777'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Abstracts/Abstract_Exporter.php#L1011
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Abstracts/Abstract_Exporter.php#L396
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Abstracts/Abstract_Exporter.php#L418
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/woocommerce-exporter/tags/2.8.0/includes/Classes/WP_Admin.php#L325
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3689535%40woocommerce-exporter&new=3689535%40woocommerce-exporter
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/c664b2b3-7ecf-4bd7-8623-3e882acfd945?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T19:35:19.772781Z'
epss: 0.00657
epssPercentile: 0.49306
ingestedAt: '2026-09-18T08:38:04.101Z'
---

## Overview

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
