Description
Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3.
Published: 2025-10-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to bypass the plugin’s intended security controls. With this weakness, an unauthorized user could gain access to the plugin’s transfer features and data that should be protected by role or permission checks. The vulnerability is classified as CWE‑862, exposing the plugin to potential confidentiality and integrity risks for any content transferred through it.

Affected Systems

WordPress sites running the Smart WeTransfer plugin version 1.3 or earlier, developed by mrityunjay.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely at this time, and the issue is not yet listed in the CISA KEV catalog. The flaw manifests when an attacker sends crafted HTTP requests to the plugin’s endpoints without the appropriate authorization, enabling remote exploitation. Because the access controls are incorrectly configured, the attacker can perform unauthenticated actions that should be restricted to privileged users.

Generated by OpenCVE AI on April 29, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Smart WeTransfer plugin to the newest available version (greater than 1.3).
  • If an upgrade is not immediately possible, disable the plugin or restrict its activation to administrator roles only.
  • Review WordPress role‑based access controls and ensure that only authorized users have permission to use the plugin’s transfer functions.

Generated by OpenCVE AI on April 29, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Tue, 28 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3.
Title WordPress Smart WeTransfer plugin <= 1.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:05.800Z

Reserved: 2025-10-24T14:24:23.977Z

Link: CVE-2025-62909

cve-icon Vulnrichment

Updated: 2025-10-27T15:17:51.929Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:50.300

Modified: 2026-04-27T18:16:29.623

Link: CVE-2025-62909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:45:19Z

Weaknesses