Critical Alert 3 Active Exploits Detected Today

CVE-2025-39964 Linux Kernel Race Condition Vulnerability →
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability →
CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-16777NVD

Description

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Severity Level
MEDIUM (4.9)
Published Date
18/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.66% (percentile 50.0%)

CVSS Base Metrics

CVSS v3 (3.1)
MEDIUM 4.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

CWE-22 - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected & Patched Versions

ProductAffected VersionsPatched Version
jkohlbach Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers0 - <= 2.8.0N/A