Impact
The BOX NOW Delivery Croatia plugin contains an unauthenticated broken access control flaw (CWE‑862). An attacker who can reach the plugin’s URLs can gain access to administrative functionality that is intended to be protected. This could allow the offender to modify shipping or delivery settings or otherwise alter the behavior of the plugin, potentially impacting the integrity and availability of the site.
Affected Systems
A WordPress website running the BOX NOW Delivery Croatia plugin developed by ivanbebek, in any version 3.3.0 or earlier, is vulnerable. Updating to version 3.3.1 or later mitigates the issue.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The potential exploitation requires no authentication and is likely achieved via HTTP requests to the plugin’s administrative endpoints. This assessment is inferred from the description; the exact attack vector is not detailed in the CVE entry, so the remote HTTP access method is a reasonable inference based on typical WordPress plugin structures.
OpenCVE Enrichment