Impact
The vulnerability is a missing authorization check in the Sendcloud Shipping WordPress plugin. It allows users without administrative privileges to access or modify shipping configuration data. The flaw is categorized as CWE‑862 and can compromise the integrity of shipping settings and expose data that should be restricted to privileged users.
Affected Systems
All releases of the Sendcloud Shipping plugin for WordPress, from the initial version up through 1.0.29, are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score of less than 1% shows the probability of exploitation is very low but non‑zero, and the vulnerability is not catalogued in the CISA KEV list. Attackers may exploit the vulnerability by sending crafted HTTP requests to the plugin’s administrative endpoints, leveraging the incorrectly configured access control to read or modify shipping data. No explicit prerequisites are noted in the description, so basic authentication or knowledge of the endpoint URL may suffice for exploitation.
OpenCVE Enrichment