Impact
The Tax Exempt for WooCommerce plugin (versions 1.9.3 and earlier) contains a customer‑controlled path traversal flaw, classified as CWE‑35. An attacker can supply an arbitrary file path to the plugin, enabling it to reference files outside its intended directory. This can that should not be accessible through the plugin interface.
Affected Systems
Addify’s Tax Exempt for WooCommerce plugin versions 1.9.3 and older. WordPress sites that have the plugin enabled are affected.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity vulnerability. The EPSS score of < 1% suggests that exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. Based on the description, it can be inferred that a remote attacker could exploit the flaw by sending crafted HTTP requests to a plugin endpoint that accepts a user triggering the traversal.
OpenCVE Enrichment