Impact
The WC Ukraine Shipping plugin for WordPress has a missing authorization flaw that permits privileged actions without proper credential checks. This defect is a classic example of broken access control (CWE‑862). An attacker who can reach the vulnerable endpoints may perform operations reserved for higher‑privilege users, potentially affecting ship data or enabling data tampering.
Affected Systems
The issue spans all installations of the Kirillbdev WC Ukraine Shipping plugin up to and including version 1.23.2. Any WordPress site that has not upgraded beyond 1.23.2 is susceptible, regardless of additional security layers.
Risk and Exploitability
The vulnerability carries a CVSS base score of 6.5, indicating medium severity. The EPSS score is unavailable, and the exploit is not listed in the CISA KEV catalog. The probable attack vector is remote and proceeds through a standard web request to the plugin’s administrative interfaces; thus a web‑connected attacker could exploit it without requiring local access.
OpenCVE Enrichment