plugin

Woocommerce Tm Extra Checkout Options Addon Vulnerabilities

1 known security issue reported for the Woocommerce Tm Extra Checkout Options Addon WordPress plugin. Most recent disclosed Jul 28, 2026.

1 high

Running Woocommerce Tm Extra Checkout Options Addon on your site? Check whether your installed version is affected.

Scan your site free

Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload in eco_save_settings

high

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authe...

CVSS:
8.8
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Jul 28, 2026

CVE-2026-14270 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database