{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/direct-download-for-woocommerce--1.19/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:direct_download_for_woocommerce_project:direct_download_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15019"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Direct Download for WooCommerce (\u003c= 1.19)"],"_cs_severities":["high"],"_cs_tags":["wordpress","web-application","cve","directory-traversal"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Direct Download for WooCommerce plugin for WordPress is affected by a directory traversal vulnerability (CVE-2026-15019) in versions up to and including 1.19. The issue arises from insufficient validation within the plugin's file download mechanism. Specifically, the top-level include function fails to ensure that requested file paths are restricted to the directory of products configured for download. Instead, the plugin only verifies the existence of a free, virtual, downloadable product on the site. An unauthenticated attacker can manipulate the file path parameter to traverse the directory structure and access sensitive system files outside the intended web root. This flaw poses a significant risk to confidentiality, potentially exposing WordPress configuration files (such as wp-config.php), environment variables, or other sensitive server data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to read arbitrary files on the WordPress server. This can lead to the exposure of database credentials, API keys, and other sensitive system information, facilitating further compromise of the WordPress environment or the underlying server infrastructure. All WordPress sites utilizing this plugin with at least one free, virtual, downloadable product configured are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u0026quot;Direct Download for WooCommerce\u0026quot; plugin to a patched version beyond 1.19 immediately.\u003c/li\u003e\n\u003cli\u003eIf a patch is not available, disable the plugin until a secure update is provided.\u003c/li\u003e\n\u003cli\u003eInspect server access logs for anomalous requests to the plugin's file download endpoints containing traversal sequences like '../'.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T05:03:49Z","date_published":"2026-09-10T05:03:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-15019-wordpress-traversal/","summary":"An unauthenticated directory traversal vulnerability in the Direct Download for WooCommerce plugin (v1.19 and below) allows attackers to read arbitrary files from the underlying server.","title":"Directory Traversal in Direct Download for WooCommerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-15019-wordpress-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Direct Download for WooCommerce (\u003c= 1.19)","version":"https://jsonfeed.org/version/1.1"}