Executive brief
A vulnerability in the WPC Product Options for WooCommerce plugin allows unauthorized individuals to download sensitive files from your web server. This plugin is used to add custom options to products on e-commerce sites. An attacker could use this flaw to steal configuration files containing database credentials or site backups, potentially leading to a full site takeover.
Technical details
The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to an arbitrary file download due to improper path validation (CWE-22: Path Traversal). The flaw exists in versions up to and including 3.2.1. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the server, allowing them to read and download sensitive files such as wp-config.php. This is achieved without any user interaction or prior authentication. The issue is resolved in version 3.2.2.
Affected products
- WPClever WPC Product Options for WooCommerce <= 3.2.1
Timeline
- 2026-05-29: other: Reported by researcher Mitchell
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date
- 2026-06-08: patched: Version 3.2.2 released to address the vulnerability