Cross Site Scripting Vulnerability in Checkout Field Editor for WooCommerce
CVE-2026-66475
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-66475?
A Cross Site Scripting (XSS) vulnerability exists in the Checkout Field Editor for WooCommerce plugin, affecting versions 3.0.5 and earlier. This vulnerability allows an attacker to inject malicious scripts into the checkout fields, which can be executed in the context of users accessing the compromised site. Users with sufficient privileges to modify checkout fields can fall victim to these attacks, leading to potential theft of sensitive information or session hijacking. It is essential for administrators to update to the latest version to mitigate this risk and ensure the safety of their e-commerce platform.
Affected Version(s)
Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved