---
id: CVE-2026-87831
title: >-
  The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin
  before 7.9.7 does not properly validate the ownership of an attachment before
  deleting it, allowing any authenticated user such as a customer to delete
  arbitr…
summary: >-
  The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin
  before 7.9.7 does not properly validate the ownership of an attachment before
  deleting it, allowing any authenticated user such as a customer to delete
  arbitr…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Checkout Field Manager (Checkout Manager) for WooCommerce
affected:
  - checkout_field_manager_checkout_manager_for_woocommerce >= 7.4.9 < 7.9.7
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87831'
references:
  - url: 'https://wpscan.com/vulnerability/7a871164-ce44-4e4c-8e15-15daa84767c6/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00254
epssPercentile: 0.15143
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:08:50.497182Z'
ingestedAt: '2026-09-17T08:14:19.082Z'
---

## Overview

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
