Extension WordPress

Vulnérabilités Checkout Field Manager (Checkout Manager) for WooCommerce

Cette page rassemble les failles publiées pour Checkout Field Manager (Checkout Manager) for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Checkout Field Manager (Checkout Manager) for WooCommerce

5 fiches

CVE-2025-13930 Moyenne · 5,3
Checkout Field Manager (Checkout Manager) for WooCommerce

Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to…

Versions affectées

*-7.8.5

Correctif

7.8.6

Publication

18/02/2026

CVE-2025-12500 Moyenne · 5,3
Checkout Field Manager (Checkout Manager) for WooCommerce

Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 – Unauthenticated Limited File Upload

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user…

Versions affectées

*-7.8.1

Correctif

7.8.2

Publication

18/02/2026

CVE-2023-47681 Moyenne · 6,5
Checkout Field Manager (Checkout Manager) for WooCommerce

WooCommerce Checkout Manager <= 7.3.0 – Missing Authorization

The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_order_attachment_upload and ajax_delete_attachment functions hooked via AJAX in versions up to, and including, 7.3.0. This makes it possible…

Versions affectées

*-7.3.0

Correctif

7.3.1

Publication

09/11/2023

Vulnérabilité Moyenne · 6,1
Checkout Field Manager (Checkout Manager) for WooCommerce

Checkout Fields Manager for WooCommerce <= 5.5.6 – Reflected Cross-Site Scripting

The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject…

Versions affectées

*-5.5.6

Correctif

5.5.7

Publication

14/06/2022

CVE-2019-11807 Élevée · 7,5
Checkout Field Manager (Checkout Manager) for WooCommerce

WooCommerce Checkout Manager <= 4.2.6 – Unauthenticated Arbitrary Media Deletion

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

Versions affectées

*-4.2.6

Correctif

4.3

Publication

25/04/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités