CVE-2026-73181

WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbitrary File Download vulnerability

Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.


We have discovered 7,058 live websites that are affected by CVE-2026-73181.

Run a Free Instant Scan




Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-73181
United States1,867 websites



Germany645 websites
GB534 websites
Netherlands404 websites
France323 websites
Spain234 websites
Italy220 websites
Russia192 websites
Iran176 websites
Australia165 websites

Website Distribution by TLD

Number of websites using CVE-2026-73181
.com2,823 websites
.co.uk408 websites
.nl376 websites
.de363 websites
.com.au175 websites
.ru165 websites
.it158 websites
.fr156 websites
.es115 websites
.net113 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73181

Top websites that are affected by CVE-2026-73181. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
**********.de Germany**,***
***.*************.com United States***,***
*******.com United States***,***
******.*****.gr Germany***,***
*********.com United States***,***
*************.com United States***,***
******.com United States***,***
***********.ir Iran***,***
************.com Switzerland***,***
See full domain list