Impact
The affected WordPress plugin contains a missing Authorization flaw that permits exploitation of incorrectly configured access‑control security levels. An attacker who successfully leverages this vulnerability could gain unauthorized access to shipping configuration settings or modify shipping‑related actions, potentially exposing sensitive business data or manipulating order fulfillment processes.
Affected Systems
Printeers Print & Ship plugin versions up to and including 1.17.0 are affected. The problem is present in all releases from the earliest unknown version through 1.17.0.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the moderate severity range. While no EPSS score is available, the lack of exploitation data suggests it has a moderate likelihood of being targeted. The vulnerability is not listed in the CISA KEV catalog. The most straightforward attack vector is remote, via the WordPress web interface or API, and can be performed by authenticated users with lower privileges or potentially by unauthenticated users depending on the plugin’s exposure.
OpenCVE Enrichment