CVE-2026-16777 Overview
CVE-2026-16777 is a directory traversal vulnerability in the Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress. The flaw affects all versions up to and including 2.8.0 and stems from unsanitized handling of the filename parameter. Authenticated attackers with shop manager privileges or higher can read arbitrary files on the underlying server. Exposed files may include WordPress configuration data, credentials, and other sensitive material stored on the host. The issue is categorized as [CWE-22] Path Traversal.
Critical Impact
Authenticated shop managers can read arbitrary files on the server, including wp-config.php and other sensitive assets, enabling further compromise of the WordPress site.
Affected Products
- Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress
- All versions up to and including 2.8.0
- WordPress installations running WooCommerce with the affected plugin enabled
Discovery Timeline
- 2026-09-18 - CVE-2026-16777 published to the National Vulnerability Database (NVD)
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-16777
Vulnerability Analysis
The vulnerability resides in the plugin's export functionality, where the filename parameter is passed to file-handling routines without sufficient validation. Because the parameter accepts traversal sequences such as ../, an authenticated attacker can escape the intended export directory and reference files elsewhere on the filesystem. The affected code paths are located in includes/Abstracts/Abstract_Exporter.php (lines 396, 418, and 1011) and includes/Classes/WP_Admin.php (line 325), per the plugin's public source references.
Exploitation requires shop manager privileges or higher, which limits the attack surface to authenticated users but does not require site administrator access. Successful exploitation results in confidentiality impact only; the vulnerability does not permit file modification or code execution directly.
Root Cause
The root cause is missing input sanitization on the filename parameter before it is used in filesystem operations. The plugin does not restrict the parameter to a whitelist of expected file names or normalize the path to enforce that resolved files remain within an intended base directory. This omission allows relative path traversal to reach arbitrary readable files under the web server's effective user.
Attack Vector
The attack is delivered over the network through the plugin's authenticated admin endpoints. An attacker with a shop manager account submits a crafted request that sets the filename parameter to a traversal payload targeting a file of interest, such as ../../../../wp-config.php. The server reads and returns the contents of that file, exposing database credentials, secret keys, and other sensitive values.
Refer to the Wordfence Vulnerability Report and the plugin source at Abstract_Exporter.php line 1011 for technical specifics.
Detection Methods for CVE-2026-16777
Indicators of Compromise
- Web server access logs containing requests to plugin export endpoints with filename values that include ../, ..\, URL-encoded traversal sequences (%2e%2e%2f), or absolute paths such as /etc/passwd.
- Unexpected outbound responses from the WordPress admin surface containing contents of wp-config.php, .env, or other server-side configuration files.
- Shop manager accounts issuing export requests at unusual frequencies or outside normal business hours.
Detection Strategies
- Inspect HTTP request logs for query strings or POST bodies with a filename parameter that resolves outside the plugin's expected export directory.
- Correlate authenticated WordPress admin sessions with file read operations by the PHP worker process using host-level auditing (auditd on Linux).
- Deploy web application firewall (WAF) rules that flag path traversal patterns targeting admin.php, admin-post.php, or plugin-specific endpoints under woocommerce-exporter.
Monitoring Recommendations
- Alert on any shop manager account activity that triggers reads of files outside the WordPress uploads directory.
- Monitor for new or modified shop manager accounts, which could indicate an adversary staging access to reach the vulnerable endpoint.
- Track plugin version inventory across WordPress sites and generate alerts when versions at or below 2.8.0 are detected.
How to Mitigate CVE-2026-16777
Immediate Actions Required
- Update the Store Exporter plugin to the version released in the fix changeset 3689535 or later.
- Audit shop manager and administrator accounts and remove any that are unused, dormant, or unrecognized.
- Rotate WordPress secret keys and database credentials if there is any indication the vulnerable endpoint was accessed.
Patch Information
The plugin author addressed the vulnerability in the changeset published on the WordPress plugin repository. Review the WordPress plugin changeset and upgrade to the fixed release. Sites running any version at or below 2.8.0 remain exposed until the update is applied.
Workarounds
- Temporarily deactivate the Store Exporter plugin until the patched version can be installed and tested.
- Restrict shop manager role assignments to a minimal set of trusted users and enforce multi-factor authentication (MFA) on all administrative accounts.
- Deploy WAF rules to block requests where the filename parameter contains traversal sequences or references files outside the plugin's expected export path.
# Example ModSecurity rule to block path traversal in the filename parameter
SecRule ARGS:filename "@rx (\.\./|\.\.\\|%2e%2e%2f|%2e%2e/)" \
"id:1026016777,phase:2,deny,status:403,log,\
msg:'CVE-2026-16777: Path traversal attempt in filename parameter'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
