CVE · Medium

CVE-2025-12500 — Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12500 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2 Unrestricted Upload of File with Dangerous Type Medium 5.3 < 7.8.2 7.8.2 2026-02-18

CVE-2025-12500

The Checkout Field Manager plugin for WooCommerce has a security flaw in versions 7.8.1 and earlier that allows unauthorized users to upload certain types of files to the server via the "ajax_checkout_attachment_upload" function without proper verification. This vulnerability is due to inadequate authorization checks within the plugin's file upload mechanism. Affected files can be restricted to specific formats, such as images or documents, but still pose a risk if exploited by malicious actors.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.