Description
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Published: 2026-08-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BOX NOW Delivery Croatia plugin contains an unauthenticated broken access control flaw (CWE‑862). An attacker who can reach the plugin’s URLs can gain access to administrative functionality that is intended to be protected. This could allow the offender to modify shipping or delivery settings or otherwise alter the behavior of the plugin, potentially impacting the integrity and availability of the site.

Affected Systems

A WordPress website running the BOX NOW Delivery Croatia plugin developed by ivanbebek, in any version 3.3.0 or earlier, is vulnerable. Updating to version 3.3.1 or later mitigates the issue.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The potential exploitation requires no authentication and is likely achieved via HTTP requests to the plugin’s administrative endpoints. This assessment is inferred from the description; the exact attack vector is not detailed in the CVE entry, so the remote HTTP access method is a reasonable inference based on typical WordPress plugin structures.

Generated by OpenCVE AI on August 6, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Update the WordPress BOX NOW Delivery Croatia Plugin to the latest available version (at least 3.3.1).


OpenCVE Recommended Actions

  • Apply the vendor‑issued patch by updating the BOX NOW Delivery Croatia plugin to version 3.3.1 or later.
  • Configure your web‑server or firewall to block unauthenticated requests to the plugin’s administrative URLs, ensuring only trusted users can reach them.
  • Review the WordPress user roles and capabilities, ensuring that only the appropriate administrator accounts have the capability to modify plugin settings.

Generated by OpenCVE AI on August 6, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Title WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:47:53.648Z

Reserved: 2026-07-22T08:53:52.510Z

Link: CVE-2026-65504

cve-icon Vulnrichment

Updated: 2026-08-06T14:47:49.943Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:00:11Z

Weaknesses