
WC Fields Factory Security & Risk Analysis
wordpress.org/plugins/wc-fields-factorySell your products with personalised options. Add custom fields to your products, variations, checkout, order and your admin screens.
Is WC Fields Factory Safe to Use in 2026?
Generally Safe
Score 90/100WC Fields Factory has a strong security track record. Known vulnerabilities have been patched promptly.
The wc-fields-factory plugin v4.1.9 presents a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and output escaping, significant concerns arise from its attack surface and the results of taint analysis. The presence of two AJAX handlers without authentication checks creates a direct entry point for potential attackers. Furthermore, the taint analysis revealing three high-severity flows with unsanitized paths is a critical finding, suggesting potential vulnerabilities that could be exploited if these flows are triggered by malicious input. Although there are no currently unpatched CVEs, the plugin has a history of two high-severity vulnerabilities, both related to SQL injection. This pattern, combined with the taint analysis findings, indicates a recurring susceptibility to injection-style attacks. While the strong adherence to prepared statements and output escaping is commendable, the unprotected AJAX endpoints and the identified high-severity taint flows represent immediate and actionable risks that must be addressed.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- History of high severity SQL injection vulnerabilities
- Missing nonce checks on AJAX
WC Fields Factory Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WC Fields Factory <= 4.1.5 - Authenticated(Subscriber+) SQL Injection
WC Fields Factory <= 4.1.5 - Authenticated (Administrator+) SQL Injection
WC Fields Factory Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WC Fields Factory Attack Surface
AJAX Handlers 2
WordPress Hooks 93
Maintenance & Trust
WC Fields Factory Maintenance & Trust
Maintenance Signals
Community Trust
WC Fields Factory Developer Profile
3 plugins · 7K total installs
How We Detect WC Fields Factory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-fields-factory/assets/css/frontend.css/wp-content/plugins/wc-fields-factory/assets/css/admin.css/wp-content/plugins/wc-fields-factory/assets/js/frontend.js/wp-content/plugins/wc-fields-factory/assets/js/admin.js/wp-content/plugins/wc-fields-factory/assets/js/frontend.js/wp-content/plugins/wc-fields-factory/assets/js/admin.jswc-fields-factory/assets/css/frontend.css?ver=wc-fields-factory/assets/css/admin.css?ver=wc-fields-factory/assets/js/frontend.js?ver=wc-fields-factory/assets/js/admin.js?ver=HTML / DOM Fingerprints
wcff_frontend_form_wrapperwcff_field_wrapperwcff_admin_form_wrapperwcff-products-page-fields-wrapperwcff-product-variations-fields-wrapperdata-wcff-field-iddata-wcff-field-typedata-wcff-field-namewcff_frontend_paramswcff_admin_params[wcff_product_fields][wcff_checkout_fields][wcff_order_fields]