CVE-2026-87831: Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with subscriber-level access or higher, including a customer account, can exploit it. No user interaction is required.
What can an attacker do?
An attacker can delete arbitrary media attachments that belong to other users. The reported impact is limited to integrity loss; confidentiality and availability impacts are not indicated.
Which plugin versions are affected?
Versions of WooCommerce Checkout Field Manager (Checkout Manager) for WooCommerce before 7.9.7 are affected. Updating to 7.9.7 or later addresses the affected version range.