plugin

Checkout Mestres Wp Vulnerabilities

5 known security issues reported for the Checkout Mestres Wp WordPress plugin. Most recent disclosed Mar 28, 2025.

4 critical 1 high

Running Checkout Mestres Wp on your site? Check whether your installed version is affected.

Scan your site free

Checkout Mestres do WP for WooCommerce 8.6.5 - 8.7.5 - Unauthenticated Arbitrary Options Update

critical

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitr...

CVSS:
9.8
Affected:
8.6.5 – 8.7.5
Fix:
No patched version reported
Disclosed:
Mar 28, 2025

CVE-2025-2266 on NVD →

Checkout Mestres WP <= 8.6 - Authenticated (Admin+) Local File Inclusion

high

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of...

CVSS:
7.2
Affected:
up to 8.6
Fixed in:
8.6.1
Disclosed:
Sep 24, 2024

CVE-2024-44030 on NVD →

Checkout Mestres WP <= 7.1.9.6 - Authentication Bypass via Password Reset

critical

The Checkout Mestres WP plugin for WordPress is vulnerable to authentication due to a weak password reset functionality in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to reset the password of arbitrary users to a guessable value based on the current time.

CVSS:
9.8
Affected:
up to 7.1.9.6
Fixed in:
7.1.9.8
Disclosed:
Dec 27, 2023

CVE-2023-51472 on NVD →

Checkout Mestres WP <= 7.1.9.6 - Missing Authorization to Unauthenticated Arbitrary Options Update

critical

The Checkout Mestres WP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to update arbitrary site options.

CVSS:
9.8
Affected:
up to 7.1.9.6
Fixed in:
7.1.9.8
Disclosed:
Dec 27, 2023

CVE-2023-51471 on NVD →

Checkout Mestres WP <= 7.1.9.6 - Unauthenticated SQL Injection

critical

The Checkout Mestres WP plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and including, 7.1.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attacke...

CVSS:
9.8
Affected:
up to 7.1.9.6
Fixed in:
7.1.9.8
Disclosed:
Dec 27, 2023

CVE-2023-51469 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database