Missing Authorization Vulnerability in Flycart's UpsellWP Plugin
CVE-2026-25419
4.3MEDIUM
What is CVE-2026-25419?
A missing authorization vulnerability exists in Flycart's UpsellWP plugin, specifically in the checkout-upsell-and-order-bumps functionality. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability affects users with UpsellWP versions from n/a through 2.2.3, highlighting the importance of securing access controls in web applications to prevent exploitation.
Affected Version(s)
UpsellWP 0 <= 2.2.5