Authorization Bypass in WooCommerce Checkout Custom Fields Builder Plugin
CVE-2026-19802
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-19802?
The Checkout Custom Fields Builder for WooCommerce plugin for WordPress has a vulnerability that allows authenticated users with subscriber-level access and above to bypass authorization checks. This flaw enables these users to install and activate arbitrary attacker-hosted plugins, leading to potential remote code execution on the server. The root cause is the inadequate verification of user permissions, which allows unauthorized actions on admin pages, particularly when WooCommerce is inactive. This vulnerability underscores the importance of ensuring proper user authorization mechanisms in plugin development.
Affected Version(s)
Checkout Custom Fields Builder for WooCommerce 0 <= 1.1.5