PLUGIN SECURITY

Is Add To Cart Direct Checkout For Woocommerce safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Add To Cart Direct Checkout For Woocommerce WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: add-to-cart-direct-checkout-for-woocommerce

Maintenance status

Known vulnerabilities

1 known CVE on file for Add To Cart Direct Checkout For Woocommerce. Reported between 2023 and 2023.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-28988 Add to Cart Redirect for WooCommerce [add-to-cart-direct-checkout-for-woocommerce] < 2.1.49 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.1.49 2.1.49 2023-03-30

CVE-2023-28988

The Direct checkout, Add to cart redirect for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 2.1.48 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.