CVE-2026-19728

HIGH CVSS 3.1: 7.5 EPSS 0.22%
Updated Aug 17, 2026
Unknown
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before 1.2.176
Type CWE-862 (Missing Authorization), CWE-862 Missing Authorization
Vendor Unknown
Public PoC No

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 writes a deny-all rule into its upload directories, so the disclosure only crosses a boundary on web servers that honour it, such as Apache. Where it is ignored, as on a default nginx setup, the same files are already served at their direct URL and the endpoint exposes nothing further.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

unknown:extra product options builder for woocommerce