Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

WooCommerce Checkout Manager plugin allows malicious scripts on admin order pages

CVE-2026-3231
Summary

The WooCommerce Checkout Manager plugin for WordPress is vulnerable to a type of attack that lets attackers inject malicious code into the admin order page. This could allow them to steal sensitive information or take control of the site. To protect your business, update the plugin to a version 2.1.8 or later.

Original title
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the ...
Original description
The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom radio and checkboxgroup field values submitted through the WooCommerce Block Checkout Store API in all versions up to, and including, 2.1.7. This is due to the `prepare_single_field_data()` method in `class-thwcfd-block-order-data.php` first escaping values with `esc_html()` then immediately reversing the escaping with `html_entity_decode()` for radio and checkboxgroup field types, combined with a permissive `wp_kses()` allowlist in `get_allowed_html()` that explicitly permits the `<select>` element with the `onchange` event handler attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via the Store API checkout endpoint that execute when an administrator views the order details page.
nvd CVSS3.1 7.2
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 11 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026