
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25419 is a Missing Authorization vulnerability in the UpsellWP WordPress plugin (also known as checkout-upsell-and-order-bumps) developed by flycart. The flaw allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels, gaining unauthorized access to restricted functionality. It affects UpsellWP versions from n/a through 2.2.5. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).
The vulnerability is classified under CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to certain actions or endpoints. An attacker with a low-privilege WordPress account (e.g., a subscriber or customer) can send crafted network requests to exploit these improperly secured access control levels without requiring user interaction. No complex attack conditions are required — the attack vector is network-based with low attack complexity and no privilege escalation beyond an initial authenticated session (Feedly).
Successful exploitation results in a limited confidentiality impact, allowing a low-privileged authenticated attacker to access data or functionality that should be restricted to higher-privileged users such as administrators. There is no direct integrity or availability impact based on the CVSS assessment. The scope is limited to the affected WordPress installation, but unauthorized access to upsell campaign data, order bump configurations, or customer order information could expose sensitive business or customer data (Feedly).
There is no public evidence of active in-the-wild exploitation of CVE-2026-25419 at this time, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term (Feedly).
wp-admin/admin-ajax.php with the relevant action parameter) targeting the improperly secured functionality.wp-admin/admin-ajax.php with UpsellWP-specific action parameters from low-privileged user accounts.Users should update the UpsellWP plugin to a version beyond 2.2.5 that includes the authorization fix. Check the WordPress plugin repository or the flycart vendor site for the latest patched release. As an interim workaround, site administrators can restrict access to the WordPress site to trusted users only, or temporarily deactivate the plugin until a patch is applied. Regularly auditing installed plugins for access control issues using tools like WPScan or Patchstack is also recommended (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."