VYPR

Checkout Field Editor for WooCommerce (Pro)

by Themehigh

CVEs (3)

  • CVE-2024-35658HigJun 10, 2024
    risk 0.56cvss 8.6epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro) allows Functionality Misuse, File Manipulation.This issue affects Checkout Field Editor for WooCommerce (Pro): from n/a through…

  • CVE-2024-8499MedOct 4, 2024
    risk 0.31cvss 4.7epss 0.00

    The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output…

  • CVE-2026-14955MedJul 25, 2026
    risk 0.00cvss 6.5epss 0.01

    The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and…