The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with subscriber-level access to read arbitrary files. This vulnerability, tracked as CVE-2026-14955, has a CVSS score of 6.5 and is considered a medium priority due to its potential for sensitive information disclosure. The vulnerability exists in all versions up to, [truncated]
CVE-2026-45217 is a medium-severity authentication bypass vulnerability in the Stripe Payment Gateway for WooCommerce WordPress plugin, affecting versions up to and including 5.0.7. The vulnerability, classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), enables password recovery exploitation, allowing attackers to potentially bypass authentication controls. The issue was publi [truncated]