
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14955 is a Directory Traversal vulnerability in the Checkout Field Editor for WooCommerce (Pro) plugin for WordPress, developed by ThemeHigh. It affects all versions up to and including 3.7.7, exploitable via the thwcfe_legacy_file parameter. The vulnerability was published on July 25, 2026, and assigned a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Wordfence).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The thwcfe_legacy_file parameter fails to properly sanitize or validate user-supplied file path input, allowing an attacker to manipulate the path to traverse outside the intended directory and access arbitrary files on the server. Exploitation requires only a low-privilege authenticated session (subscriber-level or above), no user interaction, and is reachable over the network with low attack complexity (GitHub Advisory, Wordfence).
Successful exploitation allows an authenticated attacker to read the contents of arbitrary files on the web server, including sensitive configuration files such as wp-config.php (which contains database credentials), environment files, and other confidential data. There is no integrity or availability impact, but the high confidentiality impact could enable credential theft and subsequent lateral movement or full site compromise. The attack is network-accessible and requires no user interaction, making it a practical threat in shared or multi-tenant hosting environments (GitHub Advisory, Wordfence).
thwcfe_legacy_file parameter with path traversal sequences (e.g., ../../wp-config.php or URL-encoded variants such as ..%2F..%2Fwp-config.php) to reference files outside the intended directory.wp-config.php), exposing database credentials, secret keys, and other sensitive configuration data that can be used for further compromise (GitHub Advisory, Wordfence).../, ..%2F, ..%252F) in the thwcfe_legacy_file parameter.thwcfe_legacy_file parameter, particularly from low-privilege authenticated users; repeated access attempts to sensitive files like wp-config.php.Update the Checkout Field Editor for WooCommerce (Pro) plugin to a version newer than 3.7.7, as a patch has been made available by ThemeHigh (GitHub Advisory). As interim mitigations, restrict subscriber-level account registration if not required for business operations, and implement network-level access controls to limit which users can access the affected plugin functionality. Monitor server logs for suspicious requests containing path traversal patterns in the thwcfe_legacy_file parameter (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."