Impact
The plugin contains a path traversal flaw that permits an attacker to delete arbitrary files on the server. If exploited, sensitive data could be removed, critical configuration files could be corrupted, or the site could be rendered inoperable, resulting in loss of service and data integrity.
Affected Systems
WordPress sites using WP Swings Membership For WooCommerce plugin version 3.1.0 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity, but the EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the plugin’s exposed endpoints, where an attacker can manipulate a file path parameter to reference and delete files outside the intended directory.
OpenCVE Enrichment