CVE · Medium

CVE-2025-58799 — Custom WooCommerce Checkout Fields Editor [add-fields-to-checkout-page-woocommerce] <= 1.3.4 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-58799 Custom WooCommerce Checkout Fields Editor [add-fields-to-checkout-page-woocommerce] <= 1.3.4 (unfixed) Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.3.4 1.3.4 2025-09-05

CVE-2025-58799

The Custom WooCommerce Checkout Fields Editor plugin for WordPress contains a vulnerability that allows an attacker to trick an administrator into performing an unauthorized action. This can be done by exploiting a missing or incorrect nonce validation in the plugin's code, which allows an attacker to bypass security checks and execute malicious actions without needing to authenticate.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.