A significant security flaw has been discovered in the Flexible Checkout Fields for WooCommerce plugin, a popular tool for WordPress websites. This vulnerability, identified as CVE-2020-36731, could allow unauthorized individuals to alter your plugin settings and even inject harmful scripts onto your site. This poses a serious risk to any WordPress e-commerce store utilizing this particular plugin.
The core of the problem lies in the plugin’s handling of settings updates. Specifically, it lacked proper checks to ensure that only authorized users could modify its configuration. This oversight, combined with insufficient measures to clean and validate user-supplied data before storing it, opened the door for both unauthorized setting changes and what is known as Stored Cross-Site Scripting (XSS).
CVE Details
- Product Name: Flexible Checkout Fields for WooCommerce plugin for WordPress (by WPDesk)
- Published Date: June 7, 2023
- Severity: High
- Status: Analyzed
Affected Products
The vulnerability impacts the Flexible Checkout Fields for WooCommerce plugin for WordPress, specifically all versions up to, and including, 2.3.1.
Current Status
This vulnerability has been thoroughly analyzed. This means security experts have examined the flaw, understood its nature, and confirmed its potential impact. While the vulnerability itself is understood, prompt action is still required by affected users.
Severity Level
Rated with a CVSS score of 7.2, this vulnerability carries a High severity rating. A high severity indicates that the flaw could have a substantial negative impact on affected systems. In this case, attackers could potentially gain control over parts of your website’s checkout process or inject malicious code that affects your customers or site visitors, leading to data breaches or reputation damage.
Possible Solutions
To protect your WordPress website, it is crucial to update the Flexible Checkout Fields for WooCommerce plugin immediately. The vulnerability has been addressed in version 2.3.2 and later. Therefore, the most effective solution is to update your plugin to version 2.3.2 or any subsequent version available. Always ensure your WordPress core, themes, and all other plugins are also kept up-to-date to maintain a strong security posture.
References
https://blog.nintechnet.com/zero-day-vulnerability-fixed-in-wordpress-flexible-checkout-fields-for-woocommerce-plugin/
https://www.wordfence.com/blog/2020/02/site-takeover-campaign-exploits-multiple-zero-day-vulnerabilities/
https://www.wordfence.com/threat-intel/vulnerabilities/id/fd12a952-2e99-41f7-b74c-55c2b7d8deed?source=cve


