Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 02 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themehigh
Themehigh checkout Field Editor For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Themehigh
Themehigh checkout Field Editor For Woocommerce Wordpress Wordpress wordpress |
Mon, 27 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 25 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Title | Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-27T13:58:42.946Z
Reserved: 2026-07-07T13:32:03.687Z
Link: CVE-2026-14955
Updated: 2026-07-27T13:58:37.110Z
Status : Deferred
Published: 2026-07-25T07:17:09.753
Modified: 2026-07-27T20:25:13.817
Link: CVE-2026-14955
No data.
OpenCVE Enrichment
Updated: 2026-08-03T19:45:07Z