WordPress Plugin Vulnerabilities
Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field
Description
The plugin does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
ACCESS CONTROLS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
Submitter
Md. Moniruzzaman Prodhan (NomanProdhan)
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-17 (about 9 hours ago)
Added
2026-09-17 (about 1 hour ago)
Last Updated
2026-09-17 (about 1 hour ago)