Missing Authorization Vulnerability in Easy Upload Files During Checkout by Fahad Mahmood
CVE-2025-62078
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2025
What is CVE-2025-62078?
A missing authorization vulnerability in the Easy Upload Files During Checkout plugin by Fahad Mahmood allows malicious users to exploit improperly configured access controls. The flaw affects versions up to 3.0.0, granting unauthorized access to sensitive functionalities, potentially leading to data exposure and other security risks.
Affected Version(s)
Easy Upload Files During Checkout 0 <= 3.0.0