Junglewise Threat Intelligence

CVE-2025-62078: Fahad Mahmood Easy Upload Files During Checkout broken access control

CVE-2025-62078 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

The Easy Upload Files During Checkout WordPress plugin allows customers to upload files during the checkout process. A broken access control vulnerability enables users with subscriber-level privileges to access or perform actions they should not be permitted to, such as viewing other customers' uploaded files or checkout data. This could expose sensitive customer information submitted during transactions.

Technical details

This is a broken access control vulnerability in the Easy Upload Files During Checkout WordPress plugin affecting versions up to 3.0.0. The vulnerability stems from incorrectly configured access control security levels that fail to properly restrict user actions based on privileges. An authenticated attacker with subscriber-level permissions can bypass authorization checks to access or manipulate resources belonging to other users. The attack requires authentication but can be exploited from the network after gaining any valid user account. A patch is available in version 3.0.1 and later.

Affected products

  • Fahad Mahmood Easy Upload Files During Checkout up to 3.0.0

Timeline

  • 2025-10-06: disclosed: Vulnerability reported to Patchstack by Legion Hunter
  • 2025-12-31: advisory: Early warning sent to Patchstack customers and published
  • 2025-12-31: patched: Patch released in version 3.0.1

References

Related threats