What the vulnerability does
01Description
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file attachments added to orders.
Explanation of Vulnerability in Simple Terms
02Summary
Order Attachments for WooCommerce versions up to 2.5.1 expose sensitive information that attackers can access over the network without authentication. The vulnerability requires specific conditions to exploit but allows unauthorized users to read data they should not have access to. Site owners should update to a version newer than 2.5.1 to close this exposure.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the plugin without logging in.
Potential impact on your site
04Site Impact
Customer or order data may be exposed to unauthenticated attackers if the site runs an affected version.
Conditions required to exploit
05Prerequisites
Network access; specific conditions must be met to trigger the vulnerability.
Key dates
06Disclosure timeline
February 28, 2025
CVE published
April 8, 2026
Record updated