The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
We have discovered 1,819 live websites that are affected by CVE-2026-14955.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,819 live websites (100% of Woo Checkout Field Editor Pro install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 31 versions ( 100% of all versions) |
| 447 websites | |
| 107 websites | |
| 99 websites | |
| 76 websites | |
| 74 websites | |
| 72 websites | |
| 69 websites | |
| 61 websites | |
| 50 websites | |
| 47 websites |
| .com | 769 websites |
| .org | 81 websites |
| .ru | 75 websites |
| .com.br | 67 websites |
| .nl | 46 websites |
| .net | 45 websites |
| .de | 40 websites |
| .it | 37 websites |
| .pl | 35 websites |
| .com.au | 27 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.com | **,*** | ||
| *******.net | **,*** | ||
| **********.de | **,*** | ||
| *********.com | ***,*** | ||
| *********.com | ***,*** | ||
| *******.com | ***,*** | ||
| ********.com | ***,*** | ||
| **********.com | ***,*** | ||
| ************.com | ***,*** | ||
| ****************.com | ***,*** |
FAQ