<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Direct Download for WooCommerce (&lt;= 1.19) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/direct-download-for-woocommerce--1.19/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 05:03:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/direct-download-for-woocommerce--1.19/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Directory Traversal in Direct Download for WooCommerce Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-15019-wordpress-traversal/</link><pubDate>Thu, 10 Sep 2026 05:03:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-15019-wordpress-traversal/</guid><description>An unauthenticated directory traversal vulnerability in the Direct Download for WooCommerce plugin (v1.19 and below) allows attackers to read arbitrary files from the underlying server.</description><content:encoded><![CDATA[<p>The Direct Download for WooCommerce plugin for WordPress is affected by a directory traversal vulnerability (CVE-2026-15019) in versions up to and including 1.19. The issue arises from insufficient validation within the plugin's file download mechanism. Specifically, the top-level include function fails to ensure that requested file paths are restricted to the directory of products configured for download. Instead, the plugin only verifies the existence of a free, virtual, downloadable product on the site. An unauthenticated attacker can manipulate the file path parameter to traverse the directory structure and access sensitive system files outside the intended web root. This flaw poses a significant risk to confidentiality, potentially exposing WordPress configuration files (such as wp-config.php), environment variables, or other sensitive server data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to read arbitrary files on the WordPress server. This can lead to the exposure of database credentials, API keys, and other sensitive system information, facilitating further compromise of the WordPress environment or the underlying server infrastructure. All WordPress sites utilizing this plugin with at least one free, virtual, downloadable product configured are at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the &quot;Direct Download for WooCommerce&quot; plugin to a patched version beyond 1.19 immediately.</li>
<li>If a patch is not available, disable the plugin until a secure update is provided.</li>
<li>Inspect server access logs for anomalous requests to the plugin's file download endpoints containing traversal sequences like '../'.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>web-application</category><category>cve</category><category>directory-traversal</category></item></channel></rss>