PLUGIN SECURITY
Is Woo Checkout For Digital Goods safe?
This plugin will remove billing address fields for downloadable and virtual products.
What this plugin does
- Slug:
woo-checkout-for-digital-goods - Author: Dotstore
- 3000+ active installs
- 90/100 rating (41 reviews on wordpress.org)
- 193722 all-time downloads
- On WordPress.org since 2015-10-29
checkout field editorCheckout for Digital Goods.custom fieldsremove checkout fieldsWooCommerce checkout
Maintenance status
- Latest known version: 3.8.4
- Last updated: 2026-05-04 11:02am GMT
- Tested up to WordPress: 6.9.7
- Requires PHP: 7.2+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
2 known CVEs on file for Woo Checkout For Digital Goods. Reported between 2018 and 2023.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-33999 | Digital Goods (Checkout Field Editor) for WooCommerce Checkout [woo-checkout-for-digital-goods] < 3.7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.7.1 | 3.7.1 | 2023-07-18 | ✓ fixed in latest |
| — | Digital Goods (Checkout Field Editor) for WooCommerce Checkout [woo-checkout-for-digital-goods] < 3.6.4 | Missing Authorization | Medium 6.3 | < 3.6.4 | 3.6.4 | 2022-03-04 | ✓ fixed in latest |
| — | Digital Goods (Checkout Field Editor) for WooCommerce Checkout [woo-checkout-for-digital-goods] < 3.6.4 | — | Unknown | < 3.6.4 | 3.6.4 | 2022-02-28 | ✓ fixed in latest |
| — | Digital Goods (Checkout Field Editor) for WooCommerce Checkout [woo-checkout-for-digital-goods] < 3.6.4 | — | Unknown | < 3.6.4 | 3.6.4 | 2022-02-28 | ✓ fixed in latest |
| CVE-2018-11633 | Digital Goods (Checkout Field Editor) for WooCommerce Checkout [woo-checkout-for-digital-goods] < 2.2 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 2.2 | 2.2 | 2018-05-31 | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 3.6.4 | 3.6.4 | — | ✓ fixed in latest |
How to fix it
Keep Woo Checkout For Digital Goods updated — 3.8.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Checkout Field Editor (Checkout Manager) for WooCommerce — 400000+ active installs — 98/100 (1056) — max PHP 8.4
- Custom WooCommerce Checkout Fields Editor — 2000+ active installs — 68/100 (18) — max PHP 8.4
- Checkout Field Editor (Checkout Manager) for WooCommerce — 2000+ active installs — 94/100 (35) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.