plugin

Woo Addon Uploads Vulnerabilities

2 known security issues reported for the Woo Addon Uploads WordPress plugin. Most recent disclosed Jan 10, 2026.

1 high 1 medium

Running Woo Addon Uploads on your site? Check whether your installed version is affected.

Scan your site free

File Uploads Addon for WooCommerce <= 1.7.3 - Missing Authorization

medium

The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.7.3
Fixed in:
1.7.4
Disclosed:
Jan 10, 2026

CVE-2026-24625 on NVD →

File Uploads Addon for WooCommerce <= 1.7.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

high

The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which...

CVSS:
7.5
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
Feb 17, 2025

CVE-2024-13622 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database