PT-2025-45011 · WordPress · Easy Upload Files During Checkout

Ahmad Salem

·

Published

2025-11-04

·

Updated

2025-11-07

·

CVE-2025-12682

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easy Upload Files During Checkout plugin for WordPress versions prior to 2.9.9
Description The Easy Upload Files During Checkout plugin for WordPress is susceptible to arbitrary JavaScript file uploads because of a lack of file type validation within the file during checkout function. This allows unauthenticated attackers to upload arbitrary JavaScript files to the server, potentially leading to remote code execution.
Recommendations Update the Easy Upload Files During Checkout plugin to version 2.9.9 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12682

Affected Products

Easy Upload Files During Checkout