CVE-2026-25419
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25419 is a Missing Authorization vulnerability in the UpsellWP WordPress plugin (also known as checkout-upsell-and-order-bumps) developed by flycart. The flaw allows authenticated attackers with low-level privileges to exploit incorrectly configured access control security levels, gaining unauthorized access to restricted functionality. It affects UpsellWP versions from n/a through 2.2.5. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).

Technical details

The vulnerability is classified under CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to certain actions or endpoints. An attacker with a low-privilege WordPress account (e.g., a subscriber or customer) can send crafted network requests to exploit these improperly secured access control levels without requiring user interaction. No complex attack conditions are required — the attack vector is network-based with low attack complexity and no privilege escalation beyond an initial authenticated session (Feedly).

Impact

Successful exploitation results in a limited confidentiality impact, allowing a low-privileged authenticated attacker to access data or functionality that should be restricted to higher-privileged users such as administrators. There is no direct integrity or availability impact based on the CVSS assessment. The scope is limited to the affected WordPress installation, but unauthorized access to upsell campaign data, order bump configurations, or customer order information could expose sensitive business or customer data (Feedly).

Exploitability

There is no public evidence of active in-the-wild exploitation of CVE-2026-25419 at this time, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the UpsellWP plugin (version ≤ 2.2.5) by inspecting plugin directories, readme files, or using tools like WPScan.
  2. Obtain low-privilege access: Register or log in as a low-privileged user (e.g., subscriber or customer) on the target WordPress site.
  3. Identify unprotected endpoints: Enumerate AJAX actions or REST API endpoints registered by the UpsellWP plugin that lack proper capability checks.
  4. Send unauthorized request: Craft and send an authenticated HTTP request (e.g., a POST to wp-admin/admin-ajax.php with the relevant action parameter) targeting the improperly secured functionality.
  5. Access restricted data: Receive a response containing data or functionality normally restricted to administrators, such as upsell campaign configurations or order information (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing repeated authenticated POST requests to wp-admin/admin-ajax.php with UpsellWP-specific action parameters from low-privileged user accounts.
  • Logs: Unusual access patterns where subscriber or customer-level accounts are triggering admin-level plugin actions.
  • Network: Automated or scripted requests to WordPress AJAX endpoints from a single IP in rapid succession, potentially indicating enumeration of plugin endpoints.

Mitigation and workarounds

Users should update the UpsellWP plugin to a version beyond 2.2.5 that includes the authorization fix. Check the WordPress plugin repository or the flycart vendor site for the latest patched release. As an interim workaround, site administrators can restrict access to the WordPress site to trusted users only, or temporarily deactivate the plugin until a patch is applied. Regularly auditing installed plugins for access control issues using tools like WPScan or Patchstack is also recommended (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16145HIGH7.2
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026
CVE-2026-18387MEDIUM6.5
  • groundhogg
NoYesAug 15, 2026
CVE-2026-16586MEDIUM6.5
  • contest-gallery
NoYesAug 15, 2026
CVE-2026-17090MEDIUM6.4
  • beaver-builder-lite-version
NoYesAug 15, 2026
CVE-2026-16146MEDIUM4.9
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management