Description
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.
Published: 2026-07-27
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows malicious script injection into WordPress checkout pages through the Checkout Field Editor for WooCommerce – Checkout Manager plugin, creating a classic cross‑site scripting condition. When exploited, an attacker could execute code in the context of visitors browsing the shop, potentially exposing session cookies, defacing pages, or redirecting users to malicious sites.

Affected Systems

The flaw exists in all installations of the acowebs Checkout Field Editor for WooCommerce – Checkout Manager plugin through version 3.0.5. The plugin is commonly used within WordPress sites running the WooCommerce e‑commerce platform.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity vulnerability. The EPSS score is 0.0014, indicating a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s admin interface, where an attacker with authorized access can insert malicious code into custom checkout fields that are later rendered on the public checkout page.

Generated by OpenCVE AI on August 3, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Checkout Field Editor for WooCommerce – Checkout Manager plugin to a release newer than 3.0.5 as soon as a fix is issued.
  • Disable or remove the plugin if an immediate update is not available.
  • Implement a site‑wide Content Security Policy that blocks inline scripts to reduce the impact of the XSS until the plugin is updated.

Generated by OpenCVE AI on August 3, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Acowebs
Acowebs checkout Field Editor For Woocommerce &#8211; Checkout Manager
Wordpress
Wordpress wordpress
Vendors & Products Acowebs
Acowebs checkout Field Editor For Woocommerce &#8211; Checkout Manager
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.
Title WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Acowebs Checkout Field Editor For Woocommerce &#8211; Checkout Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:22:36.892Z

Reserved: 2026-07-27T09:50:27.375Z

Link: CVE-2026-66475

cve-icon Vulnrichment

Updated: 2026-07-27T16:22:32.148Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:11.963

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-66475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')