Medium severity4.3NVD Advisory· Published Sep 17, 2026
CVE-2026-87829
CVE-2026-87829
Description
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
Affected products
1- Range: <7.9.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.