Checkout Field Visibility for eCommerce

Checkout Field Visibility for eCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).

The one issue recorded for Checkout Field Visibility for eCommerce has a vendor fix available, so running the current release closes it.

All of these findings were reported by Dimas Maulana. Checkout Field Visibility for eCommerce is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Checkout Field Visibility for eCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-39391

Checkout Field Visibility for WooCommerce <= 1.3.0 - Unauthenticated Local File Inclusion

Read the full analysis

Vulnerability Records

1 records
Checkout Field Visibility for eCommerce banner
Latestv2.0.0

Checkout Field Visibility for eCommerce

zamartz

Author

zamartz

0.0(0)
0/100
Last Updated
2026-07-06 (2mo ago)
Active Installs
50+
Downloads
4,488
Requires WP
5.0.0+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2020-04-24 (7y ago)

The biggest update to Checkout Field Visibility yet — version 2.0.0 adds full WooCommerce Checkout Blocks support. The plugin adds administrative functionality to the checkout allowing for conditional logic to unset Billing and Shipping Fields. Multiple rule sets can be applied to the same checkout allowing one condition or many to unset a single field or multiple fields at the same time. WooCommerce Checkout Blocks support (2.0.0): Rules now apply to both classic shortcode checkout and the modern Checkout block. Field visibility, required states, section hiding, terms/create-account/logged-in rules, and ruleset messages are supported on block checkout. Add the Store Notices block above checkout to display qualifying ruleset messages. This no-coding approach helps achieve removing checkout features not needed for country specific checkouts or if trying to get email acquisitions with a freemium model. NEW, you can now update the “Requred” stats of fields and show WARNING, ERROR messages at chekout based on the RuleSet This adds additional functionality and support to the legacy plugin WooCommerce Hide Bulling Fields. Users of the legacy plugin that have a paid version of this extension will have a one click option to import their previous rules. Unset Conditions base on: (both shipping and billing) Order Total Value Order Sub-Total Value Order Shipping Amount Order Tax Amount User or Admin Roles Product(s) in Cart Product Variant(s) in Cart Product Category(ies) in Cart Coupon is Applied Activation Install and Activate Plugin through the &#8216;Plugins’ menu in WordPress Goto Settings in YourSiteDomain/wp-admin/admin.php?page=wc-settings&tab=products&section=disqus_comments_and_ratings Free – Use Select Option and Save Advanced – Add API Cridentials and Save Advanced – Activate API Advanced – Choose Setting for Both Reviews and Comments and Save Buy Updgrade Purchase the Advanced option to allow additional rules and logic to be applied to both Shipping and Billing fields = WooCommerce Checkout Field Visability

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C