DEV Community

BitofWP
BitofWP

Posted on • Originally published at bitofwp.com on

1

WooCommerce Checkout Manager 4.2.6 Vulnerability

The WooCommerce Checkout Manager has been reported by PluginVulnerabilities.com for being vulnerable in arbitrary file uploads. The exploit could be activated by an unauthenticated remote attacker when the plugin “Categorize Uploaded Files” option is enabled.

In this case, the attacker cloud brute-force or guess an existing order id number and execute arbitrary server-side script code in the WooCommerce website with the active WooCommerce Checkout Manager plugin.



Apparently, WooCommerce Checkout Manager vulnerability was caught by the WordPress repository review stuff which resulted in de-activating plugin’s listing for wordpress.org.

If your WooCommerce website is using the WooCommerce Checkout Manager plugin then you should either disable “Categorize Uploaded Files” option in the setting or disable and remove the plugin completely until a new patched version becomes available from the plugin developer.

The post WooCommerce Checkout Manager 4.2.6 Vulnerability appeared first on WordPress Support Services by BitofWP.

Billboard image

The Next Generation Developer Platform

Coherence is the first Platform-as-a-Service you can control. Unlike "black-box" platforms that are opinionated about the infra you can deploy, Coherence is powered by CNC, the open-source IaC framework, which offers limitless customization.

Learn more

Top comments (0)

A Workflow Copilot. Tailored to You.

Pieces.app image

Our desktop app, with its intelligent copilot, streamlines coding by generating snippets, extracting code from screenshots, and accelerating problem-solving.

Read the docs

👋 Kindness is contagious

Please leave a ❤️ or a friendly comment on this post if you found it helpful!

Okay