PT-2026-47685 · WordPress · Recover Exit For Woocommerce

Published

2026-06-09

·

Updated

2026-06-10

·

CVE-2026-9662

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Recover Exit For WooCommerce versions prior to 1.0.4
Description The plugin is subject to Local File Inclusion due to insufficient validation and sanitization of the tpf POST parameter within the recover exit() function. This allows unauthenticated attackers to use path traversal to include unintended local PHP files, potentially leading to the exposure of sensitive information or remote code execution depending on the server configuration.
Recommendations Update to a version later than 1.0.3. As a temporary workaround, restrict access to the recover exit() function or sanitize the tpf parameter to prevent path traversal.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-9662

Affected Products

Recover Exit For Woocommerce