Directory Traversal Vulnerability in Checkout Field Editor for WooCommerce Plugin
CVE-2026-14955

6.5MEDIUM

What is CVE-2026-14955?

The Checkout Field Editor for WooCommerce (Pro) plugin in WordPress is susceptible to a directory traversal vulnerability through the 'thwcfe_legacy_file' parameter. Authenticated users, even those with basic subscriber-level permissions, could exploit this weakness to access and read sensitive files on the server. This could lead to unauthorized exposure of confidential information, heightening the security risks for affected sites.

Affected Version(s)

Checkout Field Editor for WooCommerce (Pro) 0 <= 3.7.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3
.