Impact
The vulnerability described is a missing authorization flaw in the WordPress Яндекс Доставка (Boxberry) plugin, allowing attackers to bypass the intended access control configuration. The description states that the plugin permits exploiting incorrectly configured access control security levels, which indicates that the plugin may allow actions beyond the permissions normally granted. However, the specific actions an attacker could execute, such as viewing or modifying shipping data, are not explicitly listed in the CVE data and are inferred from the description.
Affected Systems
The defect exists in the akazanstev Яндекс Доставка (Boxberry) WordPress plugin for all releases up to and including version 2.34. Administrators and users of WordPress sites running these plugin versions are affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium impact, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. The plugin is not listed in CISA’s KEV catalog. Attackers would need the ability to reach the plugin’s administrative interfaces or leverage an existing authenticated session to exploit the broken access control; this prerequisite is inferred from the text rather than being explicitly stated.
OpenCVE Enrichment