Path Traversal Vulnerability in WP Swings Membership For WooCommerce
CVE-2026-57709

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57709?

A vulnerability in WP Swings Membership For WooCommerce allows attackers to exploit improper limitations on pathname restrictions. This Path Traversal vulnerability can enable unauthorized access to sensitive files on the server, potentially leading to arbitrary file deletion. The flaw is found in versions of the Membership For WooCommerce plugin from n/a through version 3.1.0, posing a significant risk of compromising web server security.

Affected Version(s)

Membership For WooCommerce 0 <= 3.1.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sebbe_alb | Patchstack Bug Bounty Program
.