CVE Database /
CVE-2019-11807
CVE · High
CVE-2019-11807 — Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-11807
|
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3 |
Unrestricted Upload of File with Dangerous Type |
High
7.5
|
< 4.3
|
4.3 |
2019-04-25 |
—
|
CVE-2019-11807
The WooCommerce Checkout Manager plugin prior to version 4.3 contains a vulnerability that permits unauthenticated users to delete media files through the admin-ajax.php endpoint. The flaw stems from improper capability validation combined with the registration of an action accessible to non-privileged users, allowing attackers to remove attachments by manipulating the wccm_default_keys_load parameter in requests to update_attachment_wccm.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings