CVE-2025-62909
Description
Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Smart WeTransfer WordPress plugin <=1.3 has a missing authorization vulnerability allowing unauthenticated attackers to exploit incorrectly configured access controls.
Vulnerability
Overview The Smart WeTransfer WordPress plugin, versions 1.3 and earlier, contains a missing authorization vulnerability. The root cause is a failure to properly enforce access control checks, specifically missing authorization, authentication, or nonce token validation in certain functions. This allows an unprivileged user to execute actions that should require higher privileges [1].
Exploitation
This vulnerability can be exploited by an attacker who does not have any special privileges. The attack vector is network-based, requiring no user interaction. The low complexity of exploitation makes it suitable for mass exploitation campaigns, where attackers target thousands of websites regardless of their size or popularity [1].
Impact
Successful exploitation allows an attacker to perform unauthorized actions, potentially leading to data exposure or modification. The CVSS v3 base score is 4.3 (Medium), indicating a moderate severity. The vulnerability is categorized as a broken access control issue [1].
Mitigation
The vendor has not released a patch for versions beyond 1.3, and users are advised to update the plugin immediately. If updating is not possible, users should contact their hosting provider or web developer for assistance. This vulnerability is known exploitation activity has been observed in the wild [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.3
- Range: <= 1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.