CyberRota Analysis
AI-GeneratedThe Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is susceptible to a Directory Traversal vulnerability that allows authenticated attackers with subscriber-level access or higher to read arbitrary files on the server. This could lead to the exposure of sensitive information stored in those files. WordPress site administrators using this plugin should prioritize applying the latest updates to mitigate potential risks.
Original NVD Description
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.