Description
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access via Broken Access Control
Action: Update Plugin
AI Analysis

Impact

The WC Ukraine Shipping plugin for WordPress has a missing authorization flaw that permits privileged actions without proper credential checks. This defect is a classic example of broken access control (CWE‑862). An attacker who can reach the vulnerable endpoints may perform operations reserved for higher‑privilege users, potentially affecting ship data or enabling data tampering.

Affected Systems

The issue spans all installations of the Kirillbdev WC Ukraine Shipping plugin up to and including version 1.23.2. Any WordPress site that has not upgraded beyond 1.23.2 is susceptible, regardless of additional security layers.

Risk and Exploitability

The vulnerability carries a CVSS base score of 6.5, indicating medium severity. The EPSS score is unavailable, and the exploit is not listed in the CISA KEV catalog. The probable attack vector is remote and proceeds through a standard web request to the plugin’s administrative interfaces; thus a web‑connected attacker could exploit it without requiring local access.

Generated by OpenCVE AI on October 5, 2026 at 20:24 UTC.

Remediation

Vendor Solution

Update the WordPress WC Ukraine Shipping plugin to the latest available version (at least 1.23.3).


OpenCVE Recommended Actions

  • Upgrade the WC Ukraine Shipping plugin to version 1.23.3 or later to apply the vendor’s fix.
  • If an immediate upgrade is not possible, disable or uninstall the vulnerable plugin until a patched version is available to eliminate exposure.
  • Review the site for any custom code or plugins that interact with wc‑ukr‑shipping and remove or secure any exposed endpoints that rely on the broken access controls.

Generated by OpenCVE AI on October 5, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.
Title WordPress WC Ukraine Shipping plugin <= 1.23.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T19:00:10.084Z

Reserved: 2026-09-30T12:43:33.093Z

Link: CVE-2026-103337

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:08.177

Modified: 2026-10-05T20:17:08.177

Link: CVE-2026-103337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses