Extension WordPress
Vulnérabilités Checkout Field Manager (Checkout Manager) for WooCommerce
Cette page rassemble les failles publiées pour Checkout Field Manager (Checkout Manager) for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Checkout Field Manager (Checkout Manager) for WooCommerce
5 fiches
Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to…
*-7.8.5
7.8.6
18/02/2026
Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 – Unauthenticated Limited File Upload
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user…
*-7.8.1
7.8.2
18/02/2026
WooCommerce Checkout Manager <= 7.3.0 – Missing Authorization
The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_order_attachment_upload and ajax_delete_attachment functions hooked via AJAX in versions up to, and including, 7.3.0. This makes it possible…
*-7.3.0
7.3.1
09/11/2023
Checkout Fields Manager for WooCommerce <= 5.5.6 – Reflected Cross-Site Scripting
The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject…
*-5.5.6
5.5.7
14/06/2022
WooCommerce Checkout Manager <= 4.2.6 – Unauthenticated Arbitrary Media Deletion
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
*-4.2.6
4.3
25/04/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.