Executive brief
A vulnerability exists in the Checkout Field Editor for WooCommerce plugin, which is used by online stores to customize their checkout pages. A user with 'Shop Manager' privileges can inject malicious scripts into the website. If another user or administrator views the affected area, these scripts could execute, potentially leading to unauthorized actions or the redirection of customers to malicious sites.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the Acowebs Checkout Field Editor for WooCommerce – Checkout Manager plugin (versions <= 3.0.5). The flaw is due to improper neutralization of input during web page generation (CWE-79). An attacker with high privileges, specifically the 'Shop Manager' role, can inject malicious HTML or JavaScript payloads into checkout field configurations. Exploitation requires a victim (such as an administrator) to interact with the affected administrative interface. Successful exploitation allows for the execution of arbitrary scripts in the context of the victim's browser session. As of the advisory date, no official patch has been confirmed.
Affected products
- Acowebs Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5
Timeline
- 2026-06-15: other: Reported by researcher Ananda Dhakal
- 2026-07-27: disclosed: Vulnerability published by Patchstack
- 2026-07-27: advisory: NVD record published