CVE · High

CVE-2022-3490 — Checkout Field Editor (Checkout Manager) for WooCommerce [woo-checkout-field-editor-pro] < 1.8.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3490 Checkout Field Editor (Checkout Manager) for WooCommerce [woo-checkout-field-editor-pro] < 1.8.0 Deserialization of Untrusted Data High 7.2 < 1.8.0 1.8.0 2022-11-07

CVE-2022-3490

The Checkout Field Editor plugin for WooCommerce contains a PHP Object Injection vulnerability affecting versions up to 1.7.2 in the 'save_plugin_settings' function, where the 'i_settings_data' parameter improperly deserializes untrusted input. Administrators can leverage this flaw to inject arbitrary PHP objects, and while the plugin itself lacks a POP chain, the presence of one in other installed plugins or themes could enable attackers to execute arbitrary code, exfiltrate sensitive information, or remove files from the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.