Tax Exempt for WooCommerce <= 1.9.3 - Authenticated (Customer+) Path Traversal
mediumThe Tax Exempt for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.3. This makes it possible for authenticated attackers, with Custom-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 4.3
- Affected:
- up to 1.9.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 29, 2026