SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-73181

HIGH · CVSS 7.5 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

WooCommerce versions prior to 7.6 are vulnerable to an unauthenticated arbitrary file download, allowing attackers to access sensitive files on the server without authentication. This could lead to data exposure and potential exploitation of the underlying system. E-commerce businesses using affected WooCommerce versions should prioritize patching to mitigate this high-severity risk.

CVE
CVE-2026-73181
Severity
HIGH
CVSS
7.5
EPSS
0.47%

Original NVD Description

Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.