WordPress Plugin Vulnerabilities

Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field

Description

The plugin does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Md. Moniruzzaman Prodhan (NomanProdhan)
Submitter
Md. Moniruzzaman Prodhan (NomanProdhan)
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-17 (about 9 hours ago)
Added
2026-09-17 (about 1 hour ago)
Last Updated
2026-09-17 (about 1 hour ago)

Other