Description
Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tax Exempt for WooCommerce plugin (versions 1.9.3 and earlier) contains a customer‑controlled path traversal flaw, classified as CWE‑35. An attacker can supply an arbitrary file path to the plugin, enabling it to reference files outside its intended directory. This can that should not be accessible through the plugin interface.

Affected Systems

Addify’s Tax Exempt for WooCommerce plugin versions 1.9.3 and older. WordPress sites that have the plugin enabled are affected.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity vulnerability. The EPSS score of < 1% suggests that exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. Based on the description, it can be inferred that a remote attacker could exploit the flaw by sending crafted HTTP requests to a plugin endpoint that accepts a user triggering the traversal.

Generated by OpenCVE AI on July 21, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of the Tax Exempt for WooCommerce plugin newer than 1.9.3 once the vendor releases a fix.
  • If an upgrade is not immediately possible, temporarily deactivate the plugin to prevent exploitation until a patch is available.
  • Configure the HTTP access to the plugin’s directory and any endpoint, using mechanisms such as .htaccess rules or equivalent.
  • Implement input validation and sanitization for path parameters within the plugin code to mitigate path traversal (CWE‑35).

Generated by OpenCVE AI on July 21, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Addify
Addify tax Exempt For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Addify
Addify tax Exempt For Woocommerce
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.
Title WordPress Tax Exempt for WooCommerce plugin <= 1.9.3 - Path Traversal vulnerability
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Addify Tax Exempt For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:07:11.768Z

Reserved: 2026-06-01T15:29:19.865Z

Link: CVE-2026-49779

cve-icon Vulnrichment

Updated: 2026-07-02T14:07:07.366Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'