CVE-2025-26764
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 22, 2025
CWE ID 862
Summary
CVE-2025-26764 is a Missing Authorization vulnerability affecting the enituretechnology Distance Based Shipping Calculator from version n/a to 2.0.22. An attacker can exploit this issue by taking advantage of incorrectly configured access control security levels, gaining unauthorized access and potential control over the affected system. This vulnerability poses a significant risk to the integrity and confidentiality of data handled by the shipping calculator. It is recommended that users immediately update to a secure version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Distance Based Shipping Calculator Plugin
Affected Vendors
- WordPress