Cross Site Scripting Vulnerability in Checkout Field Editor for WooCommerce
CVE-2026-66475

5.9MEDIUM

What is CVE-2026-66475?

A Cross Site Scripting (XSS) vulnerability exists in the Checkout Field Editor for WooCommerce plugin, affecting versions 3.0.5 and earlier. This vulnerability allows an attacker to inject malicious scripts into the checkout fields, which can be executed in the context of users accessing the compromised site. Users with sufficient privileges to modify checkout fields can fall victim to these attacks, leading to potential theft of sensitive information or session hijacking. It is essential for administrators to update to the latest version to mitigate this risk and ensure the safety of their e-commerce platform.

Affected Version(s)

Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.