Junglewise Threat Intelligence

CVE-2026-14270: ThemeComplete Extra Checkout Options arbitrary file upload via RCE

CVE-2026-14270 · Severity: high · CVSS 8.8 · Published 2026-07-29

Executive brief

The Extra Checkout Options plugin for WordPress, which adds custom fields to WooCommerce checkout pages, contains a security flaw that allows users with basic account access to take over the website. By exploiting a weakness in how the plugin saves settings and handles file uploads, an attacker can upload malicious scripts to the server. This can lead to a complete compromise of the website, including the theft of customer data or the disruption of business operations.

Technical details

The vulnerability stems from two primary issues: missing authorization and nonce validation in the eco_save_settings() function, and insufficient authorization on the wc_eco_upload_file AJAX action. Authenticated attackers with Subscriber-level permissions can exploit the first flaw to modify the 'tc_eco_custom_file_types' setting, adding PHP to the list of allowed file extensions. Subsequently, the attacker can use the frontend upload nonce (typically available on cart or checkout pages) to upload a malicious PHP file via the AJAX action. This results in remote code execution (RCE) on the underlying server. The vulnerability is present in all versions up to and including 2.3.2, with a partial fix noted in version 2.3.2.

Affected products

  • ThemeComplete Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References