ZeroHour

CVE-2026-81774

moderate

Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment

CVSS 3.1
7.5 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-81774 is an unauthenticated sensitive data exposure flaw (CWE-497, exposure of sensitive information to an unauthorized control sphere) in the WooCommerce Product Attachment plugin for WordPress, affecting all versions up to and including 2.3.3 and scored 7.5 (High) with a fully network-based, low-complexity attack vector. An unauthenticated remote attacker can trigger it by sending ordinary HTTP requests to the plugin's exposed functionality, with no login, privileges, or user interaction required. The attacker gains read access to sensitive data handled or exposed by the plugin or host site (high confidentiality impact only; no integrity or availability impact per the CVSS score). Affected parties are WordPress e-commerce sites running WooCommerce with WooCommerce Product Attachment installed at version 2.3.3 or earlier. As of this advisory the flaw is not known to be exploited: EPSS is 0.3% (23rd percentile), it is not in CISA's KEV, and no public proof-of-concept exists.

What to do: Update WooCommerce Product Attachment to the latest vendor release (any version newer than 2.3.3) as soon as one is available. Until patched, restrict access to plugin-managed attachment files and endpoints, review web logs for unauthenticated requests to them, and assume any sensitive documents served through the plugin may have been quietly read.

Affected
WooCommerce Product Attachment (WordPress plugin)all versions <= 2.3.3
Estimated exposure
moderatelikely on the order of thousands of sites (estimated; no authoritative active-install count available) — Estimated from deployment patterns of niche WooCommerce add-on plugins, which typically have thousands of active installs within WordPress's large e-commerce ecosystem; the advisory data contains no per-plugin install or internet-exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.

Ecosystems
WordPress, E-commerce
Weakness
CWE-497
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.