Known vulnerabilities in Extra Fees for WooCommerce
Charge extra fees in cart, based on the combination of multiple conditional rules that you configure.
1Reported vulnerabilities
4.3Highest CVSS score
4.4.0Latest version
7,000+Active installs
What to do now
Update Extra Fees for WooCommerce to 4.3.4 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-39671 | Medium | 0.1% | 4.3.3 and earlier | 4.3.4 |
February 19, 2026 |