CVE Database /
CVE-2025-12500
CVE · Medium
CVE-2025-12500 — Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12500
|
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2 |
Unrestricted Upload of File with Dangerous Type |
Medium
5.3
|
< 7.8.2
|
7.8.2 |
2026-02-18 |
—
|
CVE-2025-12500
The Checkout Field Manager plugin for WooCommerce has a security flaw in versions 7.8.1 and earlier that allows unauthorized users to upload certain types of files to the server via the "ajax_checkout_attachment_upload" function without proper verification. This vulnerability is due to inadequate authorization checks within the plugin's file upload mechanism. Affected files can be restricted to specific formats, such as images or documents, but still pose a risk if exploited by malicious actors.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings