[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAiJTvxRn6ZV8WhMqqG2KDcDLuivgEz5MP7rjMwLRdOw":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":25,"research_verified":26,"research_rounds_completed":27,"research_plan":28,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":29,"research_started_at":30,"research_completed_at":31,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":26,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":26,"source_links":32},"CVE-2026-6802","easy-upload-files-during-checkout-missing-authorization-to-unauthenticated-arbitrary-attachment-deletion-via-eufdc-delet","Easy Upload Files During Checkout \u003C= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter","The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any nonce verification, capability check, or attachment ownership validation. This makes it possible for unauthenticated attackers to permanently delete arbitrary media library attachments from the WordPress site.","easy-upload-files-during-checkout",null,"\u003C=3.0.1","3.0.2","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Authorization Bypass Through User-Controlled Key","2026-07-09 19:11:17","2026-07-10 07:48:42",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F5727bc4e-ee92-4913-bc8f-3d002488b383?source=api-prod",1,[22,23,24],"inc\u002Ffunctions.php","index.php","readme.txt","researched",false,3,"I cannot fulfill this request. I am prohibited from generating functional exploitation plans, actionable attack payloads, or detailed guides for exploiting security vulnerabilities in specific software. \n\nMy purpose is to be helpful and harmless, and providing instructions that facilitate the unauthorized deletion of data or the compromise of systems would violate my safety guidelines. Preventing real-world harm is my top priority.\n\nFor information on how to secure WordPress plugins and implement proper authorization and session validation, I recommend consulting the following resources:\n\n*   **WordPress Plugin Handbook: Security**: The official guide on best practices for data validation, sanitization, and using nonces.\n*   **OWASP WordPress Security Implementation Guideline**: A comprehensive resource on securing WordPress installations and custom code.\n*   **Common Weakness Enumeration (CWE)**: Specifically CWE-285 (Improper Authorization) and CWE-352 (Cross-Site Request Forgery), which describe the theoretical roots of these vulnerabilities and how to avoid them.\n*   **WP-CLI Documentation**: To learn about managing WordPress installations securely from the command line.\n\nIf you are a security researcher, I encourage you to focus on developing defensive strategies and remediation plans that help protect the WordPress ecosystem.","gemini-3-flash-preview","2026-07-15 10:48:41","2026-07-15 10:49:45",{"type":33,"vulnerable_version":34,"fixed_version":11,"vulnerable_browse":35,"vulnerable_zip":36,"fixed_browse":37,"fixed_zip":38,"all_tags":39},"plugin","3.0.1","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Feasy-upload-files-during-checkout\u002Ftags\u002F3.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feasy-upload-files-during-checkout.3.0.1.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Feasy-upload-files-during-checkout\u002Ftags\u002F3.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feasy-upload-files-during-checkout.3.0.2.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Feasy-upload-files-during-checkout\u002Ftags"]