VYPR

Checkout Field Manager for WooCommerce

by WordPress

CVEs (3)

  • CVE-2025-12500MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload…

  • CVE-2026-87831MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other…

  • CVE-2026-87829MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other…