CVE-2026-77693
Deferred Deferred - Pending Action

Arbitrary File Deletion in Order Tip for WooCommerce Plugin

Vulnerability report for CVE-2026-77693, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-14
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
order_tip woocommerce to 1.6.0 (exc)
wp_tips order_tip_for_woocommerce to 1.6.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Order Tip for WooCommerce WordPress plugin before version 1.6.0. It allows users with the Shop Manager role or higher to delete arbitrary files on the server due to missing capability checks and path restrictions in the delete_exported_csv_file_ajax function. This could lead to a complete site takeover.

Detection Guidance

Check if the 'Order Tip for WooCommerce' plugin version is below 1.6.0. Inspect server logs for suspicious file deletion requests from users with Shop Manager role or higher. Look for AJAX calls to 'delete_exported_csv_file_ajax' function.

Impact Analysis

An attacker with Shop Manager privileges or higher could delete critical files on the server, potentially causing the website to crash or be taken over. This includes deleting configuration files, plugins, or core WordPress files, leading to full system compromise.

Compliance Impact

This vulnerability could lead to unauthorized file deletion, potentially compromising data integrity and availability. For GDPR, it may violate Article 32 (security of processing) if personal data is lost. For HIPAA, it could breach the integrity and availability requirements under the Security Rule.

Mitigation Strategies

Update the 'Order Tip for WooCommerce' plugin to version 1.6.0 or later immediately. Remove unnecessary user roles with Shop Manager capabilities. Monitor server file system for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77693. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart