What is CVE-2026-14955?
CVE-2026-14955: The Checkout Field Editor for WooCommerce (Pro) WordPress plugin contains a Directory Traversal vulnerability in versions up to 3.7.7. Authenticated attackers with subscriber-level access or higher can read sensitive file contents on the server via the 'thwcfe_legacy_file' parameter. Immediate plugin update is strongly recommended.
Azərbaycanca: CVE-2026-14955: "Checkout Field Editor for WooCommerce (Pro)" WordPress pluginində 3.7.7 və əvvəlki versiyalarda "Directory Traversal" zəifliyi aşkar edilib. Bu, "thwcfe_legacy_file" parametri vasitəsilə autentifikasiya olunmuş (abunəçi və yuxarı rol) istifadəçilərə serverdəki həssas faylların məzmununu oxumağa imkan verir. Pluginin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which user roles are affected by the CVE-2026-14955 vulnerability?
This vulnerability can be exploited by authenticated users with subscriber-level access or higher roles.
What action is recommended to mitigate CVE-2026-14955?
It is strongly recommended to immediately update the Checkout Field Editor for WooCommerce (Pro) plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.