Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plasmatizemedia
Plasmatizemedia recover Exit For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Plasmatizemedia
Plasmatizemedia recover Exit For Woocommerce Wordpress Wordpress wordpress |
Tue, 09 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter before it is used in an `include()` path in the `recover_exit()` function. This makes it possible for unauthenticated attackers to perform path traversal and include unintended local PHP files, which can lead to sensitive information exposure and, in certain deployment chains, code execution. | |
| Title | Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' Parameter | |
| Weaknesses | CWE-98 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-09T14:55:09.688Z
Reserved: 2026-05-26T22:28:08.137Z
Link: CVE-2026-9662
Updated: 2026-06-09T14:55:04.132Z
Status : Deferred
Published: 2026-06-09T05:16:41.350
Modified: 2026-06-09T13:33:34.393
Link: CVE-2026-9662
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:56:15Z