Description
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Published: 2026-08-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BOX NOW Delivery Croatia plugin contains an unauthenticated broken access control flaw (CWE‑862). An attacker who can reach the plugin’s URLs can gain access to administrative functionality that is intended to be protected. This could allow the offender to modify shipping or delivery settings or otherwise alter the behavior of the plugin, potentially impacting the integrity and availability of the site.

Affected Systems

A WordPress website running the BOX NOW Delivery Croatia plugin developed by ivanbebek, in any version 3.3.0 or earlier, is vulnerable. Updating to version 3.3.1 or later mitigates the issue.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The potential exploitation requires no authentication and is likely achieved via HTTP requests to the plugin’s administrative endpoints. This assessment is inferred from the description; the exact attack vector is not detailed in the CVE entry, so the remote HTTP access method is a reasonable inference based on typical WordPress plugin structures.

Generated by OpenCVE AI on August 6, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Update the WordPress BOX NOW Delivery Croatia Plugin to the latest available version (at least 3.3.1).


OpenCVE Recommended Actions

  • Apply the vendor‑issued patch by updating the BOX NOW Delivery Croatia plugin to version 3.3.1 or later.
  • Configure your web‑server or firewall to block unauthenticated requests to the plugin’s administrative URLs, ensuring only trusted users can reach them.
  • Review the WordPress user roles and capabilities, ensuring that only the appropriate administrator accounts have the capability to modify plugin settings.

Generated by OpenCVE AI on August 6, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Ivanbebek
Ivanbebek box Now Delivery Croatia
Wordpress
Wordpress wordpress
Vendors & Products Ivanbebek
Ivanbebek box Now Delivery Croatia
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Title WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ivanbebek Box Now Delivery Croatia
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:47:53.648Z

Reserved: 2026-07-22T08:53:52.510Z

Link: CVE-2026-65504

cve-icon Vulnrichment

Updated: 2026-08-06T14:47:49.943Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:14.697

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-65504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:00:05Z

Weaknesses