๐Ÿ” CVE Alert

CVE-2026-19728

UNKNOWN 0.0

Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 writes a deny-all rule into its upload directories, so the disclosure only crosses a boundary on web servers that honour it, such as Apache. Where it is ignored, as on a default nginx setup, the same files are already served at their direct URL and the endpoint exposes nothing further.

Vendor unknown
Product extra product options builder for woocommerce
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown extra product options builder for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown extra product options builder for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Extra Product Options Builder for WooCommerce
0 < 1.2.176

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fd10aaab-d358-4d2f-aafa-dbfba09b7fff/

Credits

Farid Narimanov WPScan