PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49779 Addify CVE debrief

A Path Traversal vulnerability was discovered in Addify Tax Exempt for WooCommerce, affecting versions from n/a before 1.9.5. This issue allows attackers to traverse paths on the server, potentially accessing sensitive files. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of Addify Tax Exempt for WooCommerce, especially those using versions prior to 1.9.5, should be aware of this vulnerability and take necessary actions to mitigate the risk.

Vendor
Addify
Product
Tax Exempt for WooCommerce
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-02
Original CVE updated
2026-07-28
Advisory published
2026-07-02
Advisory updated
2026-07-28

Who should care

Users of Addify Tax Exempt for WooCommerce, especially those using versions prior to 1.9.5, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes updating the plugin to version 1.9.5 or later, reviewing server logs for suspicious activity, and implementing additional monitoring for potential exploitation attempts. Affected operators, platforms, and security teams should prioritize vulnerability management and review compensating controls for exposed systems.

Technical summary

The vulnerability, identified as CVE-2026-49779, is a Path Traversal issue in the Addify Tax Exempt for WooCommerce plugin. It has a CVSS score of 6.5 and a severity of MEDIUM. The vulnerability exists due to the plugin's failure to properly sanitize user input, allowing attackers to access files outside the intended directory. Affected product context indicates that users of Addify Tax Exempt for WooCommerce, especially those using versions prior to 1.9.5, should take necessary actions to mitigate the risk.

Defensive priority

Medium priority should be given to updating the Addify Tax Exempt for WooCommerce plugin to version 1.9.5 or later to mitigate this vulnerability. Additional defensive measures include reviewing server logs, implementing monitoring, and verifying affected scope.

Recommended defensive actions

  • Update Addify Tax Exempt for WooCommerce to version 1.9.5 or later
  • Review server logs for suspicious activity
  • Implement additional monitoring for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record was published on 2026-07-02T12:17:29.923Z and last modified on 2026-07-28T15:17:15.530Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected scope and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-02T12:17:29.923Z and has not been modified since then. The NVD entry is currently Deferred.