---
id: CVE-2026-78371
title: >-
  The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not
  verify that the person requesting a customer-uploaded file is the customer who
  uploaded it, allowing unauthenticated attackers who know or guess a file's
  name …
summary: >-
  The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not
  verify that the person requesting a customer-uploaded file is the customer who
  uploaded it, allowing unauthenticated attackers who know or guess a file's
  name …
severity: none
cwe:
  - CWE-639
product: File Uploads Addon for WooCommerce
affected:
  - file_uploads_addon_for_woocommerce >= 1.7.2 < 1.7.6
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T06:16:58.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78371'
references:
  - url: 'https://wpscan.com/vulnerability/7a9cda53-c62a-4249-baf2-7f25feeed17a/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T06:13:49.196Z'
---

## Overview

The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
