WordPress security by component
Checkout Field Editor for WooCommerce (Pro)
Plugin description
Checkout Field Editor for WooCommerce (Pro) is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 25, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
checkout-field-editor-for-woocommerce-proLatest vulnerability
CVE-2026-14955: Checkout Field Editor Pro legacy-file parameter permits arbitrary file reads
Checkout Field Editor for WooCommerce (Pro) through 3.7.7 accepts a caller-controlled filesystem path in the thwcfe_legacy_file parameter without confining it to the intended directory. Any authenticated user, including a Subscriber, can supply traversal sequences that make the plugin read arbitrary server files and disclose sensitive contents. The CNA record does not disclose the vulnerable endpoint, action or function that consumes the parameter.
| Safe version |
|
||
|---|---|---|---|
| Jul 25, 2026 |
CVE-2026-14955
Checkout Field Editor Pro legacy-file parameter permits arbitrary file reads
Checkout Field Editor for WooCommerce (Pro) through 3.7.7 accepts a caller-controlled filesystem path in the thwcfe_legacy_file parameter without confining it to the intended directory. Any authenticated user, including a Subscriber, can supply traversal sequences that make the plugin read arbitrary server files and disclose sensitive contents. The CNA record does not disclose the vulnerable endpoint, action or function that consumes the parameter.
|
3.7.8 |
CVE6.5
NVDPending
|