
File Uploads Addon for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-addon-uploadsLet customers upload files directly on your WooCommerce product page — no more chasing emails for artwork, logos, prescriptions, or documents.
Is File Uploads Addon for WooCommerce Safe to Use in 2026?
Generally Safe
Score 96/100File Uploads Addon for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "woo-addon-uploads" plugin v1.7.3 exhibits a mixed security posture. On the positive side, the code shows excellent practices regarding SQL query sanitization and output escaping, with near-perfect adherence. The absence of a large attack surface with entry points like AJAX handlers, REST API routes, and shortcodes is also a strong indicator of good design. However, significant concerns arise from its vulnerability history. The presence of two known CVEs, with one still unpatched and categorized as high severity, alongside a pattern of "Missing Authorization" and "Exposure of Sensitive Information," is alarming. Furthermore, the taint analysis reveals a flow with an unsanitized path, suggesting a potential for path traversal or similar vulnerabilities, even if not classified as critical or high severity in the static analysis.
The plugin's strengths lie in its secure coding practices for database interactions and output handling. The low attack surface is also a positive. However, the persistent and high-severity past vulnerabilities, coupled with the identified unsanitized path flow, overshadow these strengths. The unpatched vulnerability indicates a lack of proactive security maintenance, making it a significant risk. Users of this plugin should exercise extreme caution due to the unresolved high-severity vulnerability and the identified code weakness.
Key Concerns
- Unpatched high severity CVE
- Flow with unsanitized path
- History of missing authorization
- History of sensitive info exposure
- One medium severity CVE unpatched
File Uploads Addon for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
File Uploads Addon for WooCommerce <= 1.7.3 - Missing Authorization
File Uploads Addon for WooCommerce <= 1.7.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
File Uploads Addon for WooCommerce Release Timeline
File Uploads Addon for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
File Uploads Addon for WooCommerce Attack Surface
WordPress Hooks 16
Maintenance & Trust
File Uploads Addon for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
File Uploads Addon for WooCommerce Alternatives
Product Add-Ons, Custom Fields, Booking & Extra Options for WooCommerce
product-add-ons-custom-fields-booking-extra-options-for-woocommerce
Create WooCommerce product addons, custom fields, and booking inputs. Perfect for appointments, services, and custom product pages.
Product File Upload for WooCommerce
products-file-upload-for-woocommerce
Professional AJAX Drag & Drop file upload for WooCommerce product pages. Allow customers to upload images, documents, and files instantly.
File Upload For WooCommerce
file-upload-for-woocommerce
A plugin For Uploading The Files On Product Pages And Checkout Pages of WooCommerce. Admin have so many controls over the plugin with a beatiful UI
Upload Add-on for Woocommerce
upload-add-on-for-woocommerce
Upload Add-on for Woocommerce
Uxkode Product Addons for WooCommerce
uxkode-product-addons-for-woocommerce
Add unlimited custom Product Add-Ons with optional customer input fields, plus single or dual Custom Buttons with full styling controls!
File Uploads Addon for WooCommerce Developer Profile
2 plugins · 5K total installs
How We Detect File Uploads Addon for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-addon-uploads/assets/css/admin-style.css/wp-content/plugins/woo-addon-uploads/assets/js/admin-script.js/wp-content/plugins/woo-addon-uploads/assets/js/frontend-script.js/wp-content/plugins/woo-addon-uploads/assets/js/select2/select2.full.min.js/wp-content/plugins/woo-addon-uploads/assets/js/frontend-script.js/wp-content/plugins/woo-addon-uploads/assets/js/admin-script.jswp-content/plugins/woo-addon-uploads/assets/js/admin-script.jswp-content/plugins/woo-addon-uploads/assets/js/frontend-script.jswp-content/plugins/woo-addon-uploads/assets/js/select2/select2.full.min.jswoo-addon-uploads/assets/css/admin-style.css?ver=woo-addon-uploads/assets/js/admin-script.js?ver=woo-addon-uploads/assets/js/frontend-script.js?ver=woo-addon-uploads/assets/js/select2/select2.full.min.js?ver=HTML / DOM Fingerprints
wau_admin_wrapperwau-admin-settings-pagewau-settings-field-wrapwau-settings-labelwau-settings-inputwau-settings-cat-wrapwau-settings-cat-labelwau-settings-cat-select+2 more<!-- Settings API init --><!-- Call back to display Settings Section information. --><!-- Display HTML for settings. --><!-- Display HTML for Catgories Setting. -->+32 moreid="wau_addon_settings[wau_enable_addon]"name="wau_addon_settings[wau_enable_addon]"id="wau_addon_settings[wau_settings_categories]"name="wau_addon_settings[wau_settings_categories][]"window.select2_ajax_urlwindow.select2_ajax_urlwindow.select2_nonceselect2_ajax_urlselect2_nonce