Description
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.22.
Published: 2025-02-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization issue in the enituretechnology Distance Based Shipping Calculator plugin, allowing attackers to access restricted functions and potentially modify shipping calculations or other administrative settings. This flaw is described as a broken access control, giving unauthenticated or insufficiently privileged users the ability to bypass security checks and exploit incorrectly configured access levels. As a result, an attacker could alter shipping cost data, compromise customer information, or disrupt the e‑commerce workflow, all of which can lead to financial loss and reputational damage.

Affected Systems

WordPress plugin enituretechnology Distance Based Shipping Calculator, versions from the earliest released through version 2.0.22. Any WordPress site that has this plugin installed and running a vulnerable version is affected.

Risk and Exploitability

The CVSS score of 5.4 classifies this issue as a moderate severity vulnerability. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and it is not listed in the CISA KEV catalog. Attackers can reach the vulnerability over the web by sending crafted requests to the plugin's endpoints, bypassing authorization checks that are supposed to restrict access to privileged administrators. Because the flaw manifests only when the plugin's access control settings are misconfigured, an attacker with basic technical knowledge could leverage this weakness to read or write protected data without requiring prior authentication.

Generated by OpenCVE AI on May 1, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Distance Based Shipping Calculator plugin to a version newer than 2.0.22
  • Restrict plugin access by ensuring only trusted admin users can configure shipping calculations
  • Conduct a comprehensive review of WordPress user permissions and audit for other missing authorization issues

Generated by OpenCVE AI on May 1, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-4238 Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22. Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.22.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00048}

epss

{'score': 0.00054}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00067}

epss

{'score': 0.00048}


Tue, 18 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 16 Feb 2025 22:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.
Title WordPress Distance Based Shipping Calculator plugin <= 2.0.22 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:40.118Z

Reserved: 2025-02-14T06:53:32.111Z

Link: CVE-2025-26765

cve-icon Vulnrichment

Updated: 2025-02-18T17:24:48.751Z

cve-icon NVD

Status : Deferred

Published: 2025-02-16T23:15:11.063

Modified: 2026-06-17T09:02:23.800

Link: CVE-2025-26765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T16:15:20Z

Weaknesses