Impact
A missing authorization flaw in the Distance Based Shipping Calculator plugin allows an attacker to modify shipping‑related configuration settings without proper permission checks. The flaw is described as incorrectly configured access control security levels. This weakness maps to CWE‑862.
Affected Systems
Versions from the earliest release through 2.0.22 are affected. Installations on versions 2.0.23 or later are not known to be affected because the impact of the change in those releases is not documented; it is therefore uncertain whether the fix resolves the issue. Removing the plugin eliminates the risk. The vendor is Eniture Technology.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% indicates a low exploitation probability. The vulnerability is not in the CISA KEV catalog. The description does not specify the attack vector; it is inferred that exploiting the flaw would require an attacker to have authenticated access with a role that can edit plugin settings or that the site’s role assignment is misconfigured.
OpenCVE Enrichment
EUVD