VYPR
Medium severity4.3NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62909

CVE-2025-62909

Description

Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Smart WeTransfer WordPress plugin <=1.3 has a missing authorization vulnerability allowing unauthenticated attackers to exploit incorrectly configured access controls.

Vulnerability

Overview The Smart WeTransfer WordPress plugin, versions 1.3 and earlier, contains a missing authorization vulnerability. The root cause is a failure to properly enforce access control checks, specifically missing authorization, authentication, or nonce token validation in certain functions. This allows an unprivileged user to execute actions that should require higher privileges [1].

Exploitation

This vulnerability can be exploited by an attacker who does not have any special privileges. The attack vector is network-based, requiring no user interaction. The low complexity of exploitation makes it suitable for mass exploitation campaigns, where attackers target thousands of websites regardless of their size or popularity [1].

Impact

Successful exploitation allows an attacker to perform unauthorized actions, potentially leading to data exposure or modification. The CVSS v3 base score is 4.3 (Medium), indicating a moderate severity. The vulnerability is categorized as a broken access control issue [1].

Mitigation

The vendor has not released a patch for versions beyond 1.3, and users are advised to update the plugin immediately. If updating is not possible, users should contact their hosting provider or web developer for assistance. This vulnerability is known exploitation activity has been observed in the wild [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.