CVE · High

CVE-2024-31267 — Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager [flexible-checkout-fields] < 4.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31267 Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager [flexible-checkout-fields] < 4.1.3 Missing Authorization High 8.8 < 4.1.3 4.1.3 2024-04-05

CVE-2024-31267

The Flexible Checkout Fields for WooCommerce plugin before version 4.1.3 contains a broken access control vulnerability that allows unauthenticated or low-privileged users to perform actions restricted to higher privilege levels. The flaw stems from missing authorization and nonce verification checks in a specific function. This issue was identified by Dhabaleshwar Das and has been resolved in version 4.1.3 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.