CVE-2026-81774
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
CVSS
7.5
High
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Sep 2, 2026 · Last modified: Sep 2, 2026 · CWE-497
0.3%EPSS · 30 days0.3%
2026-09-032026-09-09
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-813945.5 MED33.6%
——10Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.1dCVE-2026-813875.5 MED35.3%
——11Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.1dCVE-2026-713307.5 HIG54.0%
——16Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.2dCVE-2026-698325.6 MED31.3%
——9Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.2dCVE-2026-697235.7 MED60.6%
——18Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.2dCVE-2026-694065.5 MED41.3%
——12Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.2d