Junglewise Threat Intelligence

CVE-2026-14955: Themehigh Checkout Field Editor for WooCommerce (Pro) Directory Traversal

CVE-2026-14955 · Severity: medium · CVSS 6.5 · Published 2026-07-25

Executive brief

The Checkout Field Editor for WooCommerce (Pro) plugin, which allows online stores to customize their checkout forms, contains a security flaw. An attacker with a basic user account on the site can exploit this to read sensitive files stored on the web server. This could lead to the exposure of configuration files, passwords, or other private data, potentially compromising the entire website.

Technical details

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to and including 3.7.7. The vulnerability exists within the 'thwcfe_legacy_file' parameter, which fails to properly sanitize user-supplied input. An authenticated attacker with subscriber-level permissions or higher can use path traversal sequences (e.g., ../) to bypass directory restrictions and read the contents of sensitive files on the server. This is a local file inclusion/directory traversal issue (CWE-22) that can lead to information disclosure. The issue is addressed in version 3.7.8.

Affected products

  • Themehigh Checkout Field Editor for WooCommerce (Pro) up to, and including, 3.7.7

Timeline

  • 2026-07-17: patched: Version 3.7.8 released.
  • 2026-07-25: disclosed: CVE published.

References