Executive brief
The Checkout Custom Fields Builder for WooCommerce is a WordPress plugin used to customize product checkout forms. A flaw allows any subscriber-level user (the lowest authenticated account type) to install malicious plugins and execute arbitrary code on the server, despite lacking the permissions normally required for this action. This can result in complete server compromise.
Technical details
The plugin fails to properly verify user authorization when performing sensitive actions like plugin installation and activation. The vulnerability exists in all versions up to 1.1.5. An authenticated attacker with subscriber-level access can exploit this by harvesting a nonce that is emitted inline on admin pages—even when WooCommerce is inactive—and using it to install and activate a malicious plugin, achieving remote code execution. The attack requires only subscriber-level access and the nonce is readily available, lowering the barrier for exploitation.
Affected products
- WP Wham Checkout Custom Fields Builder for WooCommerce up to 1.1.5
Timeline
- 2026-09-09: disclosed