CVE-2026-81774
moderateUnauthenticated Sensitive Data Exposure in WooCommerce Product Attachment
CVE-2026-81774 is an unauthenticated sensitive data exposure flaw (CWE-497, exposure of sensitive information to an unauthorized control sphere) in the WooCommerce Product Attachment plugin for WordPress, affecting all versions up to and including 2.3.3 and scored 7.5 (High) with a fully network-based, low-complexity attack vector. An unauthenticated remote attacker can trigger it by sending ordinary HTTP requests to the plugin's exposed functionality, with no login, privileges, or user interaction required. The attacker gains read access to sensitive data handled or exposed by the plugin or host site (high confidentiality impact only; no integrity or availability impact per the CVSS score). Affected parties are WordPress e-commerce sites running WooCommerce with WooCommerce Product Attachment installed at version 2.3.3 or earlier. As of this advisory the flaw is not known to be exploited: EPSS is 0.3% (23rd percentile), it is not in CISA's KEV, and no public proof-of-concept exists.
What to do: Update WooCommerce Product Attachment to the latest vendor release (any version newer than 2.3.3) as soon as one is available. Until patched, restrict access to plugin-managed attachment files and endpoints, review web logs for unauthenticated requests to them, and assume any sensitive documents served through the plugin may have been quietly read.
| WooCommerce Product Attachment (WordPress plugin) | all versions <= 2.3.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
- Ecosystems
- WordPress, E-commerce
- Weakness
- CWE-497
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.