Input validation vulnerability in Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager 2.3.2

The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to security issues. Version 2.3.1 and earlier are at risk of Unauthenticated Arbitrary Plugin Settings update, as well as Stored Cross-Site Scripting. This is because the updateSettingsAction() function does not have proper authorization checks and the settings are not properly sanitized or escaped.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.