CVE · High

CVE-2019-11807 — Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-11807 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 4.3 Unrestricted Upload of File with Dangerous Type High 7.5 < 4.3 4.3 2019-04-25

CVE-2019-11807

The WooCommerce Checkout Manager plugin prior to version 4.3 contains a vulnerability that permits unauthenticated users to delete media files through the admin-ajax.php endpoint. The flaw stems from improper capability validation combined with the registration of an action accessible to non-privileged users, allowing attackers to remove attachments by manipulating the wccm_default_keys_load parameter in requests to update_attachment_wccm.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.