A vulnerability was found in WP Cost Estimation Plugin up to 9.642 on WordPress and classified as critical. The impacted element is the function lfb_upload_form. Such manipulation leads to missing authorization.

This vulnerability is documented as CVE-2019-25296. The attack can be executed remotely. There is not any exploit available.