CVE · Medium

CVE-2025-13930 — Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13930 Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6 Missing Authorization Medium 5.3 < 7.8.6 7.8.6 2026-02-18

CVE-2025-13930

The WooCommerce Checkout Field Manager plugin has a security issue affecting versions up to 7.8.5, allowing unauthorized users to remove file attachments linked to guest orders by exploiting a weakness in access controls and order ownership verification. This vulnerability stems from the plugin's failure to ensure that only authorized individuals can delete attachments. As a result, unauthenticated attackers can use publicly accessible security tokens to delete these files.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.