Executive brief
A vulnerability exists in the Checkout Files Upload for WooCommerce plugin, which allows customers to upload files during the checkout process. An attacker can exploit this flaw to bypass security checks and access sensitive files or data belonging to other users. This could lead to the exposure of private customer information or business documents uploaded during transactions.
Technical details
The WP Wham Checkout Files Upload for WooCommerce plugin (versions up to and including 2.2.5) is vulnerable to an Insecure Direct Object Reference (IDOR) classified as CWE-639. The vulnerability stems from an authorization bypass through user-controlled keys, where the application fails to properly validate the identity of the user requesting a specific resource. An unauthenticated remote attacker can exploit this by manipulating input parameters to access files or data they are not authorized to view. This issue is resolved in version 2.2.6.
Affected products
- WP Wham Checkout Files Upload for WooCommerce <= 2.2.5
Timeline
- 2026-04-09: other: Reported by researcher devploit
- 2026-05-12: advisory: Patchstack advisory published
- 2026-05-27: disclosed: CVE published to NVD