CVE-2025-62078: WordPress Easy Upload Files During Checkout plugin <= 3.0.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through 3.0.0.
Other sources
Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62078?
The severity of CVE-2025-62078 is considered critical due to the potential for unauthorized access.
How do I fix CVE-2025-62078?
To fix CVE-2025-62078, update the Easy Upload Files During Checkout plugin to the latest version.
What systems are affected by CVE-2025-62078?
CVE-2025-62078 affects versions of the Easy Upload Files During Checkout plugin from n/a up to 3.0.0.
What type of vulnerability is CVE-2025-62078?
CVE-2025-62078 is categorized as a missing authorization vulnerability.
Can CVE-2025-62078 allow for data leakage?
Yes, CVE-2025-62078 can potentially allow attackers to access sensitive user data due to insufficient access controls.