Impact
Missing Authorization vulnerability in the Easy Upload Files During Checkout plugin allows a user without proper privileges to upload files during the checkout process. Attackers can exploit this to place arbitrary files in the website’s file system, potentially leading to code execution or defacement. The weakness is identified as CWE‑862 – Broken Access Control.
Affected Systems
The flaw affects the WordPress plugin Easy Upload Files During Checkout delivered by Fahad Mahmood. Versions from the initial release up to and including 3.0.0 are impacted. No specific sub‑versions are listed beyond the ≤3.0.0 range.
Risk and Exploitability
The CVSS score of 4.3 classifies this as a Low severity vulnerability, and the EPSS score of less than 1% indicates a very low probability of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog, and there are no known public exploits. The attack vector is inferred to be through the plugin’s checkout interface, requiring an authenticated or unauthenticated web session to interact with the upload feature. Successful exploitation would grant an adversary non‑privileged file write capability within the web root.
OpenCVE Enrichment