CyberRota Analysis
AI-GeneratedWooCommerce versions prior to 7.6 are vulnerable to an unauthenticated arbitrary file download, allowing attackers to access sensitive files on the server without authentication. This could lead to data exposure and potential exploitation of the underlying system. E-commerce businesses using affected WooCommerce versions should prioritize patching to mitigate this high-severity risk.
CVE
CVE-2026-73181
Severity
HIGH
CVSS
7.5
EPSS
0.47%
Original NVD Description
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.