Description
Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.19.
Published: 2025-04-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the WordPress plugin Small Package Quotes – Worldwide Express Edition. Incorrectly configured access control security levels allow a user to invoke plugin functionality that should be restricted. This can enable an attacker to read or modify data, execute privileged actions, or otherwise compromise the site’s integrity. The primary impact is unauthorized access to sensitive data or administrative functions within the plugin.

Affected Systems

The flaw affects all installations of the Small Package Quotes – Worldwide Express Edition plugin from the earliest release up to and including version 5.2.19. Any WordPress site that has not upgraded beyond 5.2.19 is potentially vulnerable.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is considered medium to high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. The exploitation vector is likely a web request to the plugin’s endpoints, and an attacker may need some authenticated access to invoke the insecure function, though lower privileged users might still succeed if the plugin fails to enforce proper capability checks. The risk is heightened on sites with many users or where the plugin exposes configuration or rate‑pricing functions.

Generated by OpenCVE AI on May 1, 2026 at 11:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Small Package Quotes – Worldwide Express Edition plugin to a version newer than 5.2.19 to receive the vendor‑issued fix.
  • If an upgrade cannot be performed immediately, disable the plugin via the WordPress admin interface or uninstall it until a patch is available.
  • Review and tighten user role capabilities to remove access to the plugin’s insecure functions, and monitor plugin activity logs for unusual or unauthorized actions.

Generated by OpenCVE AI on May 1, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14792 Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.19.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.19. Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-quotes-wwe-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through <= 5.2.19.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Thu, 03 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 13:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.19.
Title WordPress Small Package Quotes – Worldwide Express Edition plugin <= 5.2.19 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:00.327Z

Reserved: 2025-03-26T09:21:45.625Z

Link: CVE-2025-30915

cve-icon Vulnrichment

Updated: 2025-04-03T15:00:09.832Z

cve-icon NVD

Status : Deferred

Published: 2025-04-03T14:15:34.623

Modified: 2026-04-23T15:27:19.160

Link: CVE-2025-30915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:30:15Z

Weaknesses