Impact
The Checkout Custom Fields Builder for WooCommerce plugin allows an authenticated user with subscriber-level or higher privileges to install and activate an arbitrary attacker‑hosted plugin by manipulating the 'plugin' parameter. Because the plugin fails to verify user authorization, the attacker can harness a nonce that is available on all admin pages for subscribers when WooCommerce is inactive, enabling the exploit without additional privileges. This flaw results in the ability to execute arbitrary code on the server, which is a classic remote code execution scenario.
Affected Systems
Versions of the Checkout Custom Fields Builder for WooCommerce plugin through 1.1.5, including all earlier releases, are affected. The vendor is Stylemix, and the product name is Checkout Custom Fields Builder for WooCommerce.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate base severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The primary attack vector is a web‑based exploitation that requires only authenticated access at the subscriber level. If an attacker gains a subscriber account, they can trigger the exploit and achieve remote code execution, providing full control over the affected WordPress installation.
OpenCVE Enrichment