Junglewise Threat Intelligence

CVE-2026-57709: WP Swings Membership For WooCommerce path traversal arbitrary file deletion

CVE-2026-57709 · Severity: high · CVSS 8.6 · Published 2026-07-13

Vendors: WP Swings.

Executive brief

WP Swings Membership For WooCommerce, a WordPress plugin used to manage membership programs on e-commerce sites, contains a security flaw that allows for unauthorized file manipulation. An attacker can exploit this to delete critical system files, potentially leading to a complete website shutdown or service disruption. This could result in significant downtime and loss of revenue for online stores relying on this plugin.

Technical details

A path traversal vulnerability (CWE-22) exists in the WP Swings Membership For WooCommerce plugin through version 3.1.0. The flaw allows an unauthenticated remote attacker to bypass directory restrictions by providing specially crafted input containing traversal sequences (e.g., ../). According to the CVSS vector and associated references, this specific path traversal leads to arbitrary file deletion. Successful exploitation allows an attacker to delete sensitive files on the server, resulting in a high impact on system availability (DoS). The issue is addressed in version 3.1.1.

Affected products

  • WP Swings Membership For WooCommerce <= 3.1.0

Timeline

  • 2026-07-13: advisory: NVD publication date
  • 3.1.1: patched: First unaffected version reported by CNA

References