Executive brief
The Extra Fees Plugin for WooCommerce, which allows online stores to add conditional charges during checkout, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By getting a logged-in manager to click a malicious link, an attacker could potentially modify plugin settings or delete configurations without authorization. This could lead to unauthorized changes in how fees are applied to customers or cause disruptions to the store's checkout process.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Dotstore Extra Fees Plugin for WooCommerce (woo-conditional-product-fees-for-checkout) due to missing nonce validation on administrative functions. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into visiting a specially crafted webpage or clicking a malicious link. Successful exploitation allows the attacker to execute unauthorized actions, such as modifying or deleting conditional fee rules, under the context of the victim's session. The issue is resolved in version 4.3.4.
Affected products
- Dotstore Extra Fees Plugin for WooCommerce <= 4.3.3
Timeline
- 2026-01-20: other: Vulnerability reported by Nguyen Ba Khanh
- 2026-02-19: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: NVD publication date
- 2026-04-29: patched: Patch information updated (fixed in 4.3.4)