Executive brief
The Tax Exempt for WooCommerce plugin, which allows online stores to manage tax-exempt customers, contains a security flaw that could allow registered customers to access sensitive files on the server. By exploiting this vulnerability, an attacker could potentially read configuration files or other private data that should not be accessible to them. This could lead to the exposure of sensitive business information or credentials, though it does not directly allow for the modification of site data.
Technical details
A path traversal vulnerability (CWE-35) exists in the Addify Tax Exempt for WooCommerce plugin for WordPress in versions up to and including 1.9.3. The flaw allows an authenticated attacker with 'Customer' level privileges to bypass directory restrictions and access files outside of the intended directory. This is achieved via insufficient sanitization of user-supplied input used in file paths. An attacker can exploit this over the network to read sensitive system or application files, potentially leading to further compromise. As of the advisory date, no official patch has been released, and users are advised to seek mitigation strategies such as web application firewalls.
Affected products
- Addify Tax Exempt for WooCommerce <= 1.9.3
Timeline
- 2026-05-27: other: Vulnerability reported by Saad Malik
- 2026-06-29: advisory: Patchstack published advisory
- 2026-07-02: disclosed: CVE published to NVD