Description
The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate an arbitrary attacker-hosted plugin, resulting in remote code execution on the server. The required nonce is emitted inline on all admin pages accessible to subscribers when WooCommerce is inactive, meaning any subscriber-level user can harvest it and trigger the exploit without any additional privileges.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Checkout Custom Fields Builder for WooCommerce plugin allows an authenticated user with subscriber-level or higher privileges to install and activate an arbitrary attacker‑hosted plugin by manipulating the 'plugin' parameter. Because the plugin fails to verify user authorization, the attacker can harness a nonce that is available on all admin pages for subscribers when WooCommerce is inactive, enabling the exploit without additional privileges. This flaw results in the ability to execute arbitrary code on the server, which is a classic remote code execution scenario.

Affected Systems

Versions of the Checkout Custom Fields Builder for WooCommerce plugin through 1.1.5, including all earlier releases, are affected. The vendor is Stylemix, and the product name is Checkout Custom Fields Builder for WooCommerce.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating moderate base severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The primary attack vector is a web‑based exploitation that requires only authenticated access at the subscriber level. If an attacker gains a subscriber account, they can trigger the exploit and achieve remote code execution, providing full control over the affected WordPress installation.

Generated by OpenCVE AI on September 9, 2026 at 10:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Checkout Custom Fields Builder for WooCommerce to the latest available version, ensuring the release is at least 1.1.6 or later if available.
  • Restrict the ability to install and activate plugins to administrator users through WordPress or WooCommerce role settings, or by using a role‑based access control plugin.
  • If the plugin is not required for business operations, deactivate and delete it to remove the vulnerability entirely.
  • Monitor the system for unauthorized plugin installation attempts, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 9, 2026 at 10:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Stylemix
Stylemix checkout Custom Fields Builder For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Stylemix
Stylemix checkout Custom Fields Builder For Woocommerce
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate an arbitrary attacker-hosted plugin, resulting in remote code execution on the server. The required nonce is emitted inline on all admin pages accessible to subscribers when WooCommerce is inactive, meaning any subscriber-level user can harvest it and trigger the exploit without any additional privileges.
Title Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Stylemix Checkout Custom Fields Builder For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T15:00:49.298Z

Reserved: 2026-08-13T20:27:12.564Z

Link: CVE-2026-19802

cve-icon Vulnrichment

Updated: 2026-09-09T15:00:46.162Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T07:16:56.370

Modified: 2026-09-09T16:17:02.130

Link: CVE-2026-19802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:07Z

Weaknesses