Directory Traversal Vulnerability in Checkout Field Editor for WooCommerce Plugin
CVE-2026-14955
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 July 2026
What is CVE-2026-14955?
The Checkout Field Editor for WooCommerce (Pro) plugin in WordPress is susceptible to a directory traversal vulnerability through the 'thwcfe_legacy_file' parameter. Authenticated users, even those with basic subscriber-level permissions, could exploit this weakness to access and read sensitive files on the server. This could lead to unauthorized exposure of confidential information, heightening the security risks for affected sites.
Affected Version(s)
Checkout Field Editor for WooCommerce (Pro) 0 <= 3.7.7