High 7.1
2026-04-08< 4.3.4
CVE-2026-39671
Minimum safe version
4.3.4
Update to 4.3.4 or later to address 6 fixable vulnerabilities
CVE-2026-39671
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Extra Fees Plugin for WooCommerce Plugin <= 3.9.3.1 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Extra Fees Plugin for WooCommerce plugin <= 3.8.1 - Sensitive Information Disclosure vulnerability
WordPress Extra Fees Plugin for WooCommerce plugin <= 3.8.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability