WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Woocommerce Checkout Manager?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Woocommerce Checkout Manager — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: woocommerce-checkout-manager
  • 90000+ instalaciones activas

checkout editorcheckout field customizercheckout fieldscheckout managerWooCommerce checkout

Estado de mantenimiento

  • Última versión conocida: 7.9.5
  • Requiere PHP: 5.6+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

4 CVEs conocidos registrados para Woocommerce Checkout Manager. Reportadas entre 2019 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-12500 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2 Carga de archivos sin restricción de tipo peligroso Media 5,3 < 7.8.2 7.8.2 2026-02-18 ✓ corregido en la última versión
CVE-2025-13930 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6 Falta de control de autorización Media 5,3 < 7.8.6 7.8.6 2026-02-18 ✓ corregido en la última versión
CVE-2023-47681 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.3.1 Falta de control de autorización Media 6,5 < 7.3.1 7.3.1 2023-11-09 ✓ corregido en la última versión
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7 Desconocido < 5.5.7 5.5.7 2022-06-14 ✓ corregido en la última versión
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7 Desconocido < 5.5.7 5.5.7 2022-06-14 ✓ corregido en la última versión
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.2.7 Desconocido < 4.2.7 4.2.7 2019-04-26 ✓ corregido en la última versión
CVE-2019-11807 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3 Carga de archivos sin restricción de tipo peligroso Alta 7,5 < 4.3 4.3 2019-04-25 ✓ corregido en la última versión
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7 Desconocido < 5.5.7 5.5.7 ✓ corregido en la última versión

CVE-2025-12500

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versions up to, and including, 7.8.1. This is due to the plugin not properly verifying that a user is authorized to perform file upload actions via the "ajax_checkout_attachment_upload" function. This makes it possible for unauthenticated attackers to upload files to the server, though file types are limited to WordPress's default allowed MIME types (images, documents, etc.).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13930

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.8.5. This is due to the plugin not properly verifying that a user is authorized to delete an attachment combined with flawed guest order ownership validation. This makes it possible for unauthenticated attackers to delete attachments associated with guest orders using only the publicly available wooccm_upload nonce and attachment ID.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-47681

No patched version is available. No reply from the vendor. Rafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress WooCommerce Checkout Manager Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has not been known to be fixed yet.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Checkout Fields Manager for WooCommerce plugin (versions <= 5.5.6). Update the WordPress Checkout Fields Manager for WooCommerce plugin to the latest available version (at least 5.5.7).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7

The Checkout Fields Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.2.7

Arbitrary File Upload vulnerability found in WordPress WooCommerce Checkout Manager plugin (version 4.2.6).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-11807

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 5.5.7

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Woocommerce Checkout Manager actualizado — 7.9.5 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.