Record summary

CVE-2020-36731 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via an admin_init hook, along with missing sanitization and escaping on the settings that are stored.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 27, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 28, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager

Browse wpdesk / Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager

Default status: unaffected

CVE ListBefore 2.3.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHFlexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings UpdateCVSS 7.2

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Settings update, in addition to Stored Cross-Site Scripting in versions up to, and including, 2.3.1. This is due to missing authorization checks on the updateSettingsAction() function which is called via an admin_init hook, along with missing sanitization and escaping on the settings that are stored.

Impact

Unauthenticated attackers can arbitrarily update plugin settings and inject stored XSS payloads, potentially taking over the WordPress site or stealing administrator credentials.

Remediation

Fixed in 2.3.2.

WeaknessesCWE-79
Authorspopcorn94
Template tagscvecve2020wordpresswp-pluginwpflexible-checkout-fieldsxssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wpdesk:flexible_checkout_fields_for_woocommerce:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/flexible-checkout-fields/"

Source: ProjectDiscovery

References

4