SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77693

HIGH · CVSS 8.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Order Tip for WooCommerce plugin for WordPress prior to version 1.6.0 is vulnerable due to insufficient user capability checks and unrestricted file deletion paths. This flaw allows users with the Shop Manager role and higher to delete arbitrary files on the server, potentially leading to full site compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-77693
Severity
HIGH
CVSS
8.7
EPSS
0.34%
WordPress

Original NVD Description

The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.