SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-81774

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

WooCommerce versions up to 2.3.3 are vulnerable to unauthenticated sensitive data exposure, allowing attackers to access confidential information without authentication. This flaw could lead to the leakage of sensitive product attachment data, posing significant risks to both businesses and customers. E-commerce platforms utilizing affected versions should prioritize immediate remediation to safeguard sensitive information.

CVE
CVE-2026-81774
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.