Impact
The BD Courier Order Ratio Checker plugin for WordPress contains missing authorization checks that result in broken access control. Attackers can exploit this flaw to access administrative features or sensitive order data that should be restricted to privileged users. The weakness corresponds to CWE‑862, indicating a failure in enforcing proper permission checks.
Affected Systems
WordPress sites running the BD Courier Order Ratio Checker plugin by Rasedul Haque Rumi, versions n/a through 2.0.1.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity, but the EPSS score is under 1%, meaning the likelihood of exploitation is low at present. The plugin is a web‑based component, so the likely attack vector is remote over HTTP/HTTPS, though an attacker requires only the ability to reach the WordPress installation without privileged access. The plugin is not listed in CISA’s KEV catalog.
OpenCVE Enrichment