Answer in brief
CVE-2026-94375 records a Medium severity (CVSS 5.3) vulnerability in Order Export & Order Import for WooCommerce <= 2.7.8 - Unauthenticated Sensitive File Exposure via Missing Directory Guard Re-verification in get_file_path(). The current sources do not mark it as known exploited. The current feed maps webtoffee/Order Export & Order Import for WooCommerce (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps webtoffee/Order Export & Order Import for WooCommerce (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| webtoffee/Order Export & Order Import for WooCommercegeneric | >=0 <=2.7.8 | Not reported |
Published upstream
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 10, 2026
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is exploitable whenever the .htaccess and index.php guard files are absent from wp-content/webtoffee_export/, which can occur after any uninstall/reinstall cycle, migration, backup restore, or staging sync, since the export directory persists but its guard files do not; export filenames follow a fully deterministic second-precision timestamp pattern, making them brute-forceable across any suspected export window.
Quoted source text, attributed separately from HOL analysis.