{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/extra-checkout-options-addon-for-extra-product-options--add-ons-for-woocommerce-plugin--2.3.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14270"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Extra Checkout Options (addon for Extra Product Options \u0026 Add-Ons for WooCommerce) plugin \u003c= 2.3.2"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","arbitrary-file-upload","rce","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress","WooCommerce"],"content_html":"\u003cp\u003eA significant security vulnerability, CVE-2026-14270, has been identified in the Extra Checkout Options plugin for WordPress, affecting all versions up to and including 2.3.2. This flaw enables low-privileged authenticated users, specifically those with Subscriber-level access or higher, to achieve remote code execution (RCE) on affected WordPress installations. The vulnerability stems from a combination of missing authorization and inadequate nonce validation within the \u003ccode\u003eeco_save_settings()\u003c/code\u003e function, which allows attackers to modify the \u003ccode\u003etc_eco_custom_file_types\u003c/code\u003e upload allowlist to include PHP files. This, coupled with insufficient authorization on the \u003ccode\u003ewc_eco_upload_file\u003c/code\u003e AJAX action, permits the upload of malicious PHP files using frontend nonces typically found on cart and checkout pages. Exploitation of this vulnerability grants attackers full control over the compromised WordPress site and potentially the underlying server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated attacker with Subscriber-level privileges or higher logs into the vulnerable WordPress site.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted HTTP POST request to \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e with the \u003ccode\u003eaction=eco_save_settings\u003c/code\u003e parameter, exploiting missing authorization and nonce validation to modify the \u003ccode\u003etc_eco_custom_file_types\u003c/code\u003e allowlist to include PHP file extensions.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to a cart or checkout page on the WordPress site to obtain a valid frontend upload nonce.\u003c/li\u003e\n\u003cli\u003eUsing the acquired nonce, the attacker sends another crafted HTTP POST request to \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e with \u003ccode\u003eaction=wc_eco_upload_file\u003c/code\u003e, uploading a malicious PHP file (e.g., a web shell).\u003c/li\u003e\n\u003cli\u003eDue to insufficient authorization on the \u003ccode\u003ewc_eco_upload_file\u003c/code\u003e AJAX action, the plugin processes and saves the malicious PHP file to an accessible directory on the WordPress server.\u003c/li\u003e\n\u003cli\u003eThe attacker then makes a direct HTTP request to the URL of the newly uploaded PHP file.\u003c/li\u003e\n\u003cli\u003eThe web server executes the malicious PHP file, granting the attacker remote code execution capabilities on the underlying system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14270 grants attackers remote code execution on the compromised WordPress server. This can lead to severe consequences, including complete takeover of the website, defacement, theft of sensitive data (such as customer information or payment details), installation of backdoors for persistent access, or using the compromised server as a platform for launching further attacks (e.g., botnet participation, phishing campaigns). The impact extends beyond the immediate website to potentially affecting customer trust and leading to significant financial and reputational damages for the affected organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Extra Checkout Options plugin to a version patched against CVE-2026-14270.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rules to your webserver logs or WAF to detect attempts to exploit CVE-2026-14270.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for HTTP POST requests to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e with \u003ccode\u003eaction=eco_save_settings\u003c/code\u003e and \u003ccode\u003erequest_body\u003c/code\u003e containing \u0026quot;php\u0026quot; within \u003ccode\u003etc_eco_custom_file_types\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for HTTP POST requests to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e with \u003ccode\u003eaction=wc_eco_upload_file\u003c/code\u003e and \u003ccode\u003erequest_body\u003c/code\u003e indicating a PHP file upload (e.g., containing \u003ccode\u003e\u0026lt;?php\u003c/code\u003e or \u003ccode\u003e.php\u003c/code\u003e in filenames).\u003c/li\u003e\n\u003cli\u003eReview file system integrity monitoring logs for unexpected PHP file creations in WordPress upload directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T12:20:19Z","date_published":"2026-07-29T12:20:19Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14270-extra-checkout-options-rce/","summary":"A critical arbitrary file upload vulnerability (CVE-2026-14270) in the Extra Checkout Options plugin for WordPress, affecting versions up to and including 2.3.2, allows low-privileged authenticated users to modify upload allowlists and upload malicious PHP files via an AJAX action, ultimately achieving remote code execution on the server.","title":"Critical Arbitrary File Upload in WordPress Extra Checkout Options Plugin Leads to RCE (CVE-2026-14270)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14270-extra-checkout-options-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Extra Checkout Options (Addon for Extra Product Options \u0026 Add-Ons for WooCommerce) Plugin \u003c= 2.3.2","version":"https://jsonfeed.org/version/1.1"}