PT-2026-43637 · Wp Wham+1 · Wp Wham Checkout Files Upload For Woocommerce+1

·

CVE-2026-42725

·

Published

2026-05-12

·

Updated

2026-05-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Checkout Files Upload for WooCommerce versions prior to 2.2.6
Description An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key, which allows unauthenticated attackers to bypass authorization and exploit incorrectly configured access control security levels to perform unauthorized actions.
Recommendations Update Checkout Files Upload for WooCommerce to version 2.2.6 or later.

Fix

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42725

Affected Products

Wp Wham Checkout Files Upload For Woocommerce
Checkout-Files-Upload-Woocommerce