VYPR

Checkout Field Editor for WooCommerce (Pro)

by WordPress

CVEs (3)

  • CVE-2024-35658HigJun 10, 2024
    risk 0.56cvss 8.6epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through…

  • CVE-2026-66475MedJul 27, 2026
    risk 0.00cvss 5.9epss 0.00

    Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions.

  • CVE-2026-14955MedJul 25, 2026
    risk 0.00cvss 6.5epss 0.01

    The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and…