Impact
Based on the description, it is inferred that the plugin contains a missing authorization flaw that permits any authenticated user to invoke privileged operations that should be restricted to administrators or privileged roles, potentially allowing unintended modification of box sizes, shipping calculations, and other configuration settings. This breach of integrity could lead to incorrect shipping charges, revenue loss, or exposure of sensitive order data.
Affected Systems
WordPress sites deploying enituretechnology Standard Box Sizes for WooCommerce version 1.6.13 or earlier are affected. The vulnerability exists across all builds from the earliest available release through 1.6.13.
Risk and Exploitability
Based on the description, it is inferred that an attacker can remotely exploit the flaw via the web interface of a WordPress site, provided they have a valid user account; the attack does not require elevated privileges or specialized tooling beyond standard authentication against the site. The CVSS score of 7.5 signals a high‑severity authorization failure. Although the EPSS score is under 1%, suggesting a low probability of exploitation at the time of this review, the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
EUVD