Impact
The Easy Upload Files During Checkout plugin contains a missing authorization check for the eufdc-delete parameter in the ufdc_custom_init function. This missing check is a CWE‑639 (Improper Authorization) flaw. Because the plugin does not verify a nonce, capability, or attachment ownership, an unauthenticated user can exploit the endpoint to delete any media library attachment. The vulnerability allows complete loss of media files from the site, potentially disrupting content and appearance.
Affected Systems
This flaw affects the WordPress plugin Easy Upload Files During Checkout 3.0.1, developed by fahadmahmood. Any WordPress site that has the plugin installed and has not applied an update after its public release is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes a moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not catalogued in the CISA KEV list. The attack vector is inferred to be a direct HTTP request to the plugin’s endpoint with the eufdc-delete parameter set, requiring no authentication. An attacker can permanently delete media attachments, which may lead to content loss and site disruption for the owner.
OpenCVE Enrichment