VYPR

Extra Checkout Options

by WordPress

CVEs (1)

  • CVE-2026-14270Jul 29, 2026
    risk 0.00cvss epss 0.01

    The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings()…