Junglewise Threat Intelligence

CVE-2026-87831: Checkout Field Manager for WooCommerce arbitrary attachment deletion

CVE-2026-87831 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Vendors: WooCommerce.

Executive brief

Checkout Field Manager is a WordPress plugin that extends WooCommerce checkout forms with custom fields. The plugin fails to verify that a customer owns an attachment before allowing deletion, enabling any logged-in customer to permanently delete media files uploaded by other users, including administrators. This could lead to loss of important product images, documents, or other critical media content.

Technical details

The plugin contains a broken access control vulnerability (CWE-284) in its attachment deletion logic. Any authenticated user, including low-privilege subscribers or WooCommerce customers, can invoke a delete operation on arbitrary media attachments without the plugin validating that they own or have permission to delete the target file. The vulnerability is reachable through a custom field in the checkout process and requires only network access and valid authentication (available to any customer account). An attacker can achieve arbitrary deletion of media attachments belonging to other users, including site administrators. The vulnerability was patched in version 7.9.7.

Affected products

  • WooCommerce Checkout Field Manager before 7.9.7

Timeline

  • 2026-09-17: disclosed: Publicly disclosed on WordPress.org and CVE databases
  • 2026-09-17: patched: Fixed in version 7.9.7

References

Related threats