Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.
Published: 2026-07-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin contains a path traversal flaw that permits an attacker to delete arbitrary files on the server. If exploited, sensitive data could be removed, critical configuration files could be corrupted, or the site could be rendered inoperable, resulting in loss of service and data integrity.

Affected Systems

WordPress sites using WP Swings Membership For WooCommerce plugin version 3.1.0 or earlier are vulnerable.

Risk and Exploitability

The CVSS score of 8.6 classifies the issue as high severity, but the EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the plugin’s exposed endpoints, where an attacker can manipulate a file path parameter to reference and delete files outside the intended directory.

Generated by OpenCVE AI on August 1, 2026 at 10:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Swings Membership For WooCommerce to a version newer than 3.1.0.
  • If an upgrade is not immediately possible, restrict write permissions on the plugin’s directory and enforce file modifications.
  • Implement application level checks that validate file paths against a whitelist of allowed directories before performing delete operations.
  • Maintain regular backups of the site’s files and databases to quickly restore any data removed by an attacker.

Generated by OpenCVE AI on August 1, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings membership For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings membership For Woocommerce

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.
Title WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Wordpress Wordpress
Wpswings Membership For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:51:42.927Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57709

cve-icon Vulnrichment

Updated: 2026-07-13T13:51:39.061Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')