Addify · Tax Exempt For Woocommerce · CVE-2026-49779
**Name of the Vulnerable Software and Affected Versions**
Tax Exempt for WooCommerce versions prior to 1.9.5
**Description**
An issue in the Addify Tax Exempt for WooCommerce plugin allows for path traversal, a condition where an attacker can access files and directories that are stored outside the web root folder by using special characters like `.../...//`.
**Recommendations**
Update Tax Exempt for WooCommerce to version 1.9.5 or later.