What is CVE-2026-14270?
CVE-2026-14270 is an arbitrary file upload vulnerability in the 'Extra Checkout Options' plugin for WordPress. It stems from missing authorization and nonce validation in the eco_save_settings() function, allowing unauthenticated attackers to upload malicious files. Versions up to and including 2.3.2 are affected, and users should update or deactivate the plugin immediately.
Azərbaycanca: CVE-2026-14270 WordPress üçün 'Extra Checkout Options' plaginində ixtiyari fayl yükləmə zəifliyidir. Bu, eco_save_settings() funksiyasında çatışmayan avtorizasiya və nonce yoxlanışı səbəbindən baş verir və autentifikasiya olunmamış hücumçulara serverə zərərli fayl yükləməyə imkan verir. Plaginin 2.3.2 və daha əvvəlki versiyaları təsirlənir, istifadəçilərə dərhal yeniləmə və ya plagini deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: WooCommerce, WordPress
FAQ2
Which versions of the 'Extra Checkout Options' plugin are affected by CVE-2026-14270?
Versions up to and including 2.3.2 are affected by this vulnerability.
What is the root cause of CVE-2026-14270?
The vulnerability stems from missing authorization and nonce validation in the eco_save_settings() function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.