CVE Explorer
CVE-2026-14270
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting, combined with insufficient authorization on the wc_eco_upload_file AJAX action. This makes it possib
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Extra Checkout Options - addon for Extra Product Options plugin","vendor":"ThemeComplete","versions":[{"lessThanOrEqual":"2.3.2","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:14a1a829c2df1778a2c2eee678344c9c9ad3b7e45e5ed2376d0988b5efac2633 · sha256:4c659a47353f60cc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:14a1a829c2df1778a2c2eee678344c9c9ad3b7e45e5ed2376d0988b5efac2633 · sha256:4c659a47353f60cc… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-434","description":"CWE-434 Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:14a1a829c2df1778a2c2eee678344c9c9ad3b7e45e5ed2376d0988b5efac2633 · sha256:4c659a47353f60cc… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://codecanyon.net/item/extra-checkout-options-addon-for-extra-product-options/20439659"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:14a1a829c2df1778a2c2eee678344c9c9ad3b7e45e5ed2376d0988b5efac2633 · sha256:4c659a47353f60cc… · /containers/cna/references/1
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a929efaf-80a1-45c1-9426-6c5b45a66530?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:14a1a829c2df1778a2c2eee678344c9c9ad3b7e45e5ed2376d0988b5efac2633 · sha256:4c659a47353f60cc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.