Impact
The vulnerability is a missing authorization flaw in the Shiptimize for WooCommerce plugin that allows an attacker to change configuration settings without proper authentication. This flaw can lead to manipulation of the plugin’s behavior, potentially affecting the functional integrity of a WooCommerce site and creating a surface for further exploitation if other administrative functions become exposed.
Affected Systems
The flaw affects the Shiptimize for WooCommerce plugin from its earliest release through version 3.1.86. Site administrators running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 5.4 places the issue in the medium range, and the EPSS score indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access via the WordPress administration interface, though the description does not specify exact conditions; this inference is based on the nature of the missing authorization check.
OpenCVE Enrichment
EUVD