Improper Attachment Deletion in WooCommerce Checkout Field Manager Plugin
CVE-2026-87829
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-87829?
The Checkout Field Manager for WooCommerce plugin prior to version 7.9.7 contains a security flaw that allows any authenticated user to delete arbitrary media attachments owned by other users. This vulnerability arises from inadequate validation of attachment ownership, which can lead to unauthorized media deletion, potentially affecting user trust and data integrity. It is essential for site administrators to update to the latest version to mitigate the risk associated with this issue.
Affected Version(s)
Checkout Field Manager (Checkout Manager) for WooCommerce 7.8.6 < 7.9.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved