Impact
The Checkout Field Manager for WooCommerce plugin fails to verify that an authenticated user owns a media attachment before deleting it. As a result, any user who has logged in to the WooCommerce store, such as a customer, can trigger the removal of any media file from the WordPress media library. This flaw enables the loss of valuable images or documents that belong to the site owner or other users, thereby compromising the integrity of the store’s content.
Affected Systems
Any WordPress site running Checkout Field Manager (Checkout Manager) for WooCommerce version 7.9.6 or earlier is affected. The vulnerability is tied to the customer address custom field deletion logic and does not require any specific WooCommerce version beyond the plugin constraint.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low but non‑zero exploitation probability. The issue is not listed in the CISA KEV catalog. The likely attack vector is through legitimate plugin functionality accessed over HTTPS by an authenticated WooCommerce user; no additional privileges are required beyond authentication. Successful exploitation results in the removal of attachments but does not grant remote code execution or broader system compromise.
OpenCVE Enrichment