PT-2026-65784 · WordPress · Extra Checkout Options

·

CVE-2026-14270

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) versions prior to 2.3.3
Description An arbitrary file upload issue exists due to missing authorization and nonce validation in the eco save settings() function. This allows authenticated users with Subscriber-level access or higher to modify the tc eco custom file types upload allowlist setting. When combined with insufficient authorization on the wc eco upload file AJAX action, attackers can enable PHP uploads and upload a PHP file using the frontend upload nonce found on cart and checkout pages, leading to remote code execution.
Recommendations Update to a version newer than 2.3.2.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14270

Affected Products

Extra Checkout Options