Showing 1 vulnerability on this page for Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager

Signals CISA KEV Ransomware Nuclei
wpdesk vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via an admin_init hook, along with missing sanitization and escaping on the settings that are stored.

CWE-79Jun 7, 20231 related artifact
CVSS7.2v3.1EPSS1.34%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX