What the vulnerability does
01Description
Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Sizes – for WooCommerce: from n/a through <= 1.6.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Sizes – for WooCommerce: from n/a through <= 1.6.13.
Explanation of Vulnerability in Simple Terms
Standard Box Sizes for WooCommerce versions 1.6.13 and earlier lack proper authorization checks. An unauthenticated attacker can modify box size data through the plugin's API or admin functions without permission. This allows unauthorized changes to product packaging settings that affect orders and shipping calculations. Update to a version newer than 1.6.13.
What an attacker can do
Modify box size settings and data without authentication or authorization.
Potential impact on your site
Attackers can alter shipping box configurations, disrupting order fulfillment and potentially causing financial loss.
Conditions required to exploit
Network access to the WordPress site; no authentication required.
Key dates
External resources
Related vulnerabilities