Loading
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
Cite this page
CVE-2019-11807. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-11807
Use CWE-434, Visser vendor hub and Woocommerce Checkout Manager product page to widen CVE-2019-11807 into its surrounding weakness, vendor, and product context.