GHSA-8fmr-v9g7-jcmfMediumCVSS 6.5
Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload...
🔗 CVE IDs covered (1)
📋 Description
Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.5.
🔗 References (3)
- https://nvd.nist.gov/vuln/detail/CVE-2026-42725
- https://patchstack.com/database/Wordpress/Plugin/checkout-files-upload-woocommerce/vulnerability/wordpress-checkout-files-upload-for-woocommerce-plugin-2-2-5-insecure-direct-object-references-idor-vulnerability?_s_id=cve
- https://github.com/advisories/GHSA-8fmr-v9g7-jcmf