CVE-2025-26764

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 22, 2025
CWE ID 862

Summary

CVE-2025-26764 is a Missing Authorization vulnerability affecting the enituretechnology Distance Based Shipping Calculator from version n/a to 2.0.22. An attacker can exploit this issue by taking advantage of incorrectly configured access control security levels, gaining unauthorized access and potential control over the affected system. This vulnerability poses a significant risk to the integrity and confidentiality of data handled by the shipping calculator. It is recommended that users immediately update to a secure version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Distance Based Shipping Calculator Plugin

Affected Vendors

  • WordPress