CVE · High

CVE-2020-36731 — Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager [flexible-checkout-fields] < 2.3.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36731 Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager [flexible-checkout-fields] < 2.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.3.2 2.3.2 2020-02-26

CVE-2020-36731

The Flexible Checkout Fields for WooCommerce plugin through version 2.3.1 contains two security issues stemming from the updateSettingsAction() function executed during the admin_init hook. An attacker can modify arbitrary plugin settings without authentication due to absent authorization validation, and malicious data can be persisted as stored cross-site scripting because the settings lack proper sanitization and output escaping.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.