Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2
unknown
[en] The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload actions via the "ajax_checkout_attac...
- Affected:
- up to 7.8.2
- Fixed in:
- 7.8.2
- Disclosed:
- Feb 19, 2026
CVE-2025-12500 on NVD →
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6
unknown
[en] The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order ownership validation....
- Affected:
- up to 7.8.6
- Fixed in:
- 7.8.6
- Disclosed:
- Feb 19, 2026
CVE-2025-13930 on NVD →
Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
medium
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order ownership validation. This...
- CVSS:
- 5.3
- Affected:
- up to 7.8.5
- Fixed in:
- 7.8.6
- Disclosed:
- Feb 18, 2026
CVE-2025-13930 on NVD →
Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 - Unauthenticated Limited File Upload
medium
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload actions via the "ajax_checkout_attachment...
- CVSS:
- 5.3
- Affected:
- up to 7.8.1
- Fixed in:
- 7.8.2
- Disclosed:
- Feb 18, 2026
CVE-2025-12500 on NVD →
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.3.1
unknown
[en] Missing Authorization vulnerability in QuadLayers WooCommerce Checkout Manager.This issue affects WooCommerce Checkout Manager: from n/a through 7.3.0.
- Affected:
- up to 7.3.1
- Fixed in:
- 7.3.1
- Disclosed:
- Jun 19, 2024
CVE-2023-47681 on NVD →
WooCommerce Checkout Manager <= 7.3.0 - Missing Authorization
medium
The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_order_attachment_upload and ajax_delete_attachment functions hooked via AJAX in versions up to, and including, 7.3.0. This makes it possible for unauthenticated attackers to update ar...
- CVSS:
- 6.5
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.1
- Disclosed:
- Nov 9, 2023
CVE-2023-47681 on NVD →
Checkout Fields Manager for WooCommerce <= 5.5.6 - Reflected Cross-Site Scripting
medium
The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...
- CVSS:
- 6.1
- Affected:
- up to 5.5.6
- Fixed in:
- 5.5.7
- Disclosed:
- Jun 14, 2022
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Checkout Fields Manager for WooCommerce plugin (versions <= 5.5.6).
Update the WordPress Checkout Fields Manager for WooCommerce plugin to the latest available version (at least 5.5.7).
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.7
- Disclosed:
- Jun 14, 2022
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7
unknown
The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.7
- Disclosed:
- Jun 14, 2022
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3
unknown
[en] The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
- Affected:
- up to 4.3
- Fixed in:
- 4.3
- Disclosed:
- May 6, 2019
CVE-2019-11807 on NVD →
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.2.7
unknown
Arbitrary File Upload vulnerability found in WordPress WooCommerce Checkout Manager plugin (version 4.2.6).
- Affected:
- up to 4.2.7
- Fixed in:
- 4.2.7
- Disclosed:
- Apr 26, 2019
WooCommerce Checkout Manager <= 4.2.6 - Unauthenticated Arbitrary Media Deletion
high
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
- CVSS:
- 7.5
- Affected:
- up to 4.2.6
- Fixed in:
- 4.3
- Disclosed:
- Apr 25, 2019
CVE-2019-11807 on NVD →
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7
unknown
The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 5.5.7
- Fixed in:
- 5.5.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database