CVE-2026-14955

Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.


We have discovered 1,819 live websites that are affected by CVE-2026-14955.

Run a Free Instant Scan




Affected Software

Product  Woo Checkout Field Editor Pro
Category Wordpress Plugins
Vulnerable Domains1,819 live websites (100% of Woo Checkout Field Editor Pro install base)
Vulnerable Versions
  • from 0 through 3.7.7
Vulnerable Versions Count31 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Jul 25, 2026
  • Updated - Jul 27, 2026

Credits

  • 0xd4rk5id3 (finder)

Website Distribution by Country

Number of websites using CVE-2026-14955
United States447 websites



Germany107 websites
Russia99 websites
Brazil76 websites
France74 websites
GB72 websites
Cyprus69 websites
Spain61 websites
Italy50 websites
India47 websites

Website Distribution by TLD

Number of websites using CVE-2026-14955
.com769 websites
.org81 websites
.ru75 websites
.com.br67 websites
.nl46 websites
.net45 websites
.de40 websites
.it37 websites
.pl35 websites
.com.au27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14955

Top websites that are affected by CVE-2026-14955. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com United States**,***
*******.net Canada**,***
**********.de Germany**,***
*********.com United States***,***
*********.com United States***,***
*******.com United States***,***
********.com GB***,***
**********.com United Arab Emirates***,***
************.com Canada***,***
****************.com United States***,***
See full domain list

FAQ

CVE-2026-14955 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Woo Checkout Field Editor Pro
A total of 1,819 websites have been identified as vulnerable to CVE-2026-14955, based on global website indexing conducted by WebTechSurvey.
The Woo Checkout Field Editor Pro is affected by the CVE-2026-14955 vulnerability.
Woo Checkout Field Editor Pro versions up to and including 3.7.7 are vulnerable to CVE-2026-14955.