CVE-2026-103337: WordPress WC Ukraine Shipping plugin <= 1.23.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kirillbdev WC Ukraine Shippingto a version that resolves this vulnerability.Fixed in 1.23.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs at least low-level privileges on the affected WordPress site. The vulnerability is remotely exploitable and does not require user interaction.
What versions are affected?
WC Ukraine Shipping versions through 1.23.2 are affected. The available data does not identify a fixed version.
What is the likely impact?
Successful exploitation can compromise integrity, meaning an attacker may be able to make unauthorized changes. No confidentiality or availability impact is identified in the provided severity vector.