Junglewise Threat Intelligence

CVE-2026-19802: Checkout Custom Fields Builder for WooCommerce authorization bypass

CVE-2026-19802 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Executive brief

The Checkout Custom Fields Builder for WooCommerce is a WordPress plugin used to customize product checkout forms. A flaw allows any subscriber-level user (the lowest authenticated account type) to install malicious plugins and execute arbitrary code on the server, despite lacking the permissions normally required for this action. This can result in complete server compromise.

Technical details

The plugin fails to properly verify user authorization when performing sensitive actions like plugin installation and activation. The vulnerability exists in all versions up to 1.1.5. An authenticated attacker with subscriber-level access can exploit this by harvesting a nonce that is emitted inline on admin pages—even when WooCommerce is inactive—and using it to install and activate a malicious plugin, achieving remote code execution. The attack requires only subscriber-level access and the nonce is readily available, lowering the barrier for exploitation.

Affected products

  • WP Wham Checkout Custom Fields Builder for WooCommerce up to 1.1.5

Timeline

  • 2026-09-09: disclosed

References