What the vulnerability does
01Description
Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0.
Explanation of Vulnerability in Simple Terms
02Summary
Easy Upload Files During Checkout versions 3.0.0 and earlier lack proper authorization checks on file upload functionality. An authenticated user with low privileges can upload files without proper validation, potentially modifying site content or injecting malicious files. The vulnerability requires an active user account but no special permissions.
What an attacker can do
03Attacker Capabilities
Upload files to the site without proper authorization checks.
Potential impact on your site
04Site Impact
Unauthorized users can upload files, risking malicious content injection or site defacement.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
December 31, 2025
CVE published
April 28, 2026
Record updated