CVE Database /
CVE-2022-3490
CVE · High
CVE-2022-3490 — Checkout Field Editor (Checkout Manager) for WooCommerce [woo-checkout-field-editor-pro] < 1.8.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3490
|
Checkout Field Editor (Checkout Manager) for WooCommerce [woo-checkout-field-editor-pro] < 1.8.0 |
Deserialization of Untrusted Data |
High
7.2
|
< 1.8.0
|
1.8.0 |
2022-11-07 |
—
|
CVE-2022-3490
The Checkout Field Editor plugin for WooCommerce contains a PHP Object Injection vulnerability affecting versions up to 1.7.2 in the 'save_plugin_settings' function, where the 'i_settings_data' parameter improperly deserializes untrusted input. Administrators can leverage this flaw to inject arbitrary PHP objects, and while the plugin itself lacks a POP chain, the presence of one in other installed plugins or themes could enable attackers to execute arbitrary code, exfiltrate sensitive information, or remove files from the system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings