CVE-2026-66475

WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.


We have discovered 2,813 live websites that are affected by CVE-2026-66475.

Run a Free Instant Scan




Affected Software

Product  Checkout Field Editor And Manager For Woocommerce
Category Wordpress Plugins
Vulnerable Domains2,813 live websites (100% of Checkout Field Editor And Manager For Woocommerce install base)
Vulnerable Versions
  • from 0 through 3.0.5
Vulnerable Versions Count49 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66475
United States540 websites



Italy217 websites
Germany172 websites
Russia167 websites
Brazil160 websites
Spain160 websites
GB85 websites
Cyprus83 websites
Iran83 websites
France78 websites

Website Distribution by TLD

Number of websites using CVE-2026-66475
.com1,093 websites
.it155 websites
.com.br138 websites
.ru136 websites
.org79 websites
.es63 websites
.nl48 websites
.co.uk47 websites
.de45 websites
.net32 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66475

Top websites that are affected by CVE-2026-66475. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.se Sweden**,***
**********.org United States**,***
********.com United States***,***
****************.ca Canada***,***
*********.****.*******.com United States***,***
********.in United Arab Emirates***,***
******************.com United States***,***
**************.***.br Brazil***,***
********.com United States***,***
*************.com France***,***
See full domain list

FAQ

CVE-2026-66475 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Checkout Field Editor And Manager For Woocommerce
A total of 2,813 websites have been identified as vulnerable to CVE-2026-66475, based on global website indexing conducted by WebTechSurvey.
The Checkout Field Editor And Manager For Woocommerce is affected by the CVE-2026-66475 vulnerability.
Checkout Field Editor And Manager For Woocommerce versions up to and including 3.0.5 are vulnerable to CVE-2026-66475.