Contribuinte Checkout
Contribuinte Checkout has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Contribuinte Checkout has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Xuan Chien. Contribuinte Checkout is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-47685Contribuinte Checkout <= 2.0.03 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Contribuinte Checkout
Author
Moloni
With this plugin you can add VAT and VIES support to your WooCommerce store. The VAT field will be saved as ‘_billing_vat’. Important: this plugin requires WooCommerce 3.0.0 or higher. Warning: to enable and use VIES information you need to have SOAP extension enabled (SoapClient PHP class). Features Adds VAT field to billing form. Adds VAT field to outgoing email. Adds VAT field to checkout billing information. Adds VAT field to admin orders page. Change VAT field label and description. Validate Portuguese VAT numbers. Choose how to handle vat field validation errors. You can make VAT field required. You can add VIES information to admin order page, checkout and user billing page. Adds settings page under WooCommerce menu so you manage all the features. Translations English. Portuguese.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C