Description
WordPress Plugin Checkout Field Editor for WooCommerce (Pro) is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Checkout Field Editor for WooCommerce (Pro) version 3.6.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.6.3 or latest
References
Related Vulnerabilities
MySQL CVE-2017-3529 Vulnerability (CVE-2017-3529)
MySQL CVE-2022-21290 Vulnerability (CVE-2022-21290)
WordPress Plugin Premmerce Permalink Manager for WooCommerce Local File Inclusion (2.3.10)
OpenSSL Numeric Errors Vulnerability (CVE-2009-0789)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-18033)