
CVE-2026-25419 Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Configured Access Control Security Levels.This i… https://www.cve.org/CVERecord?id=CVE-2026-25419
Post summary
The text announces a missing‑authorization flaw in Flycart’s UpsellWP checkout‑upsell‑and‑order‑bumps plugin, noting that poorly configured access controls enable exploitation.
