CVE-2026-14955

medium

Description

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/a9576cee-2375-437e-9dc8-713209a96a73?source=cve

https://www.themehigh.com/product/woocommerce-checkout-field-editor-pro/

Details

Source: Mitre, NVD

Published: 2026-07-25

Updated: 2026-07-27

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00526