CVE-2019-11807: Visser Woocommerce Checkout Manager

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

Affected products

  • Visser Woocommerce Checkout Manager: before 4.3 (fixed in 4.3)

Published 2019-05-06. Last modified 2026-06-17.