CVE-2026-77693: CWE-73 External Control of File Name or Path in Order Tip for WooCommerce
Description
The Order Tip for WooCommerce WordPress plugin before version 1.6.0 contains a vulnerability that allows users with the Shop Manager role or higher to delete arbitrary files on the server. This occurs because the plugin does not verify user capabilities for file deletion requests and does not restrict the file paths that can be deleted. Exploitation of this vulnerability could lead to site takeover.
CVSS v3.1
Score 8.7high
Affected software
Order Tip for WooCommerce
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-77693 is a vulnerability in the Order Tip for WooCommerce plugin for WordPress, affecting versions prior to 1.6.0. The flaw arises from improper access control and path validation in the file deletion functionality, allowing users with Shop Manager privileges or higher to delete arbitrary files on the server. This external control of file name or path (CWE-73) can result in a complete site compromise if exploited.
Potential Impact
Users with Shop Manager role or higher can delete arbitrary files on the server due to missing capability checks and path restrictions. This can lead to denial of service or full site takeover, impacting site integrity and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict Shop Manager and higher roles from accessing the vulnerable plugin functionality or remove the plugin if not needed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-21T07:47:22.095Z
- State
- PUBLISHED
Threat ID: 6a8e82bcacd9273b4979d4a4
Added to database: 08/26/2026, 06:07:56 UTC
Last enriched: 09/09/2026, 19:52:40 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 30
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.