CVE-2026-57709: WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/WP Swings Membership For WooCommerce (membership-for-woocommerce)to a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57709?
The severity of CVE-2026-57709 is rated as high with a score of 8.6.
How do I fix CVE-2026-57709?
To fix CVE-2026-57709, update the Membership For WooCommerce plugin to version 3.1.1 or later.
What is the impact of CVE-2026-57709?
CVE-2026-57709 allows for arbitrary file deletion due to a Path Traversal vulnerability.
Which versions of Membership For WooCommerce are affected by CVE-2026-57709?
CVE-2026-57709 affects all versions of the Membership For WooCommerce plugin from its initial release to version 3.1.0.
What type of vulnerability is CVE-2026-57709?
CVE-2026-57709 is classified as a Path Traversal vulnerability.