CVE-2026-87829: Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with subscriber-level access or higher, including a customer account, can exploit it. No administrator privileges are required.
What access does an attacker need before exploiting it?
The attacker needs a valid authenticated account and must be able to submit an attachment ID that refers to media owned by another user. The vulnerability is remotely reachable and does not require user interaction.
What is the impact on affected sites?
An attacker can delete arbitrary media attachments belonging to other users. The reported impact is limited to integrity; confidentiality and availability impacts are not indicated.
Which versions are affected?
Versions of Checkout Field Manager for WooCommerce WordPress plugin before 7.9.7 are affected. Updating to version 7.9.7 or later addresses the affected version range.