plugin

Woocommerce Checkout Manager Vulnerabilities

13 known security issues reported for the Woocommerce Checkout Manager WordPress plugin. Most recent disclosed Feb 19, 2026.

1 high 4 medium

Running Woocommerce Checkout Manager on your site? Check whether your installed version is affected.

Scan your site free

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2

unknown

[en] The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload actions via the "ajax_checkout_attac...

Affected:
up to 7.8.2
Fixed in:
7.8.2
Disclosed:
Feb 19, 2026

CVE-2025-12500 on NVD →

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6

unknown

[en] The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order ownership validation....

Affected:
up to 7.8.6
Fixed in:
7.8.6
Disclosed:
Feb 19, 2026

CVE-2025-13930 on NVD →

Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

medium

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order ownership validation. This...

CVSS:
5.3
Affected:
up to 7.8.5
Fixed in:
7.8.6
Disclosed:
Feb 18, 2026

CVE-2025-13930 on NVD →

Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 - Unauthenticated Limited File Upload

medium

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload actions via the "ajax_checkout_attachment...

CVSS:
5.3
Affected:
up to 7.8.1
Fixed in:
7.8.2
Disclosed:
Feb 18, 2026

CVE-2025-12500 on NVD →

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.3.1

unknown

[en] Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.0.

Affected:
up to 7.3.1
Fixed in:
7.3.1
Disclosed:
Jun 19, 2024

CVE-2023-47681 on NVD →

WooCommerce Checkout Manager <= 7.3.0 - Missing Authorization

medium

The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_order_attachment_upload and ajax_delete_attachment functions hooked via AJAX in versions up to, and including, 7.3.0. This makes it possible for unauthenticated attackers to update ar...

CVSS:
6.5
Affected:
up to 7.3.0
Fixed in:
7.3.1
Disclosed:
Nov 9, 2023

CVE-2023-47681 on NVD →

Checkout Fields Manager for WooCommerce <= 5.5.6 - Reflected Cross-Site Scripting

medium

The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 5.5.6
Fixed in:
5.5.7
Disclosed:
Jun 14, 2022

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Checkout Fields Manager for WooCommerce plugin (versions <= 5.5.6). Update the WordPress Checkout Fields Manager for WooCommerce plugin to the latest available version (at least 5.5.7).

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
Jun 14, 2022

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7

unknown

The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
Jun 14, 2022

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3

unknown

[en] The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

Affected:
up to 4.3
Fixed in:
4.3
Disclosed:
May 6, 2019

CVE-2019-11807 on NVD →

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.2.7

unknown

Arbitrary File Upload vulnerability found in WordPress WooCommerce Checkout Manager plugin (version 4.2.6).

Affected:
up to 4.2.7
Fixed in:
4.2.7
Disclosed:
Apr 26, 2019

WooCommerce Checkout Manager <= 4.2.6 - Unauthenticated Arbitrary Media Deletion

high

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

CVSS:
7.5
Affected:
up to 4.2.6
Fixed in:
4.3
Disclosed:
Apr 25, 2019

CVE-2019-11807 on NVD →

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 5.5.7
Fixed in:
5.5.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database