CVE-2026-49779: WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability
Published Jul 2, 2026
·Updated
Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal.
This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.
Affected Software
2 affected components
addify Tax Exempt for WooCommerce<1.9.5
wordpress-plugin/Tax Exempt for WooCommerce<1.9.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tax Exempt for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 1.9.5
Event History
Jul 2, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49779?
CVE-2026-49779 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-49779?
To mitigate CVE-2026-49779, update the Tax Exempt for WooCommerce plugin to version 1.9.4 or later.
3
What type of vulnerability is CVE-2026-49779?
CVE-2026-49779 is classified as a Path Traversal vulnerability.
4
What impact does CVE-2026-49779 have on WordPress?
CVE-2026-49779 allows attackers to exploit customer path traversal in versions up to 1.9.3 of the Tax Exempt for WooCommerce plugin.
5
When was CVE-2026-49779 published?
CVE-2026-49779 was published on July 2, 2026.