Broken Access Control in Joovii Sendle Shipping Plugin by WordPress
CVE-2025-62976
5.3MEDIUM
What is CVE-2025-62976?
The Joovii Sendle Shipping plugin for WordPress has a vulnerability that allows unauthorized access to functionalities not properly constrained by access control lists (ACLs). This flaw affects versions of the plugin from n/a up to version 6.02, potentially exposing sensitive operations to unauthorized users and increasing security risks for affected WordPress sites.
Affected Version(s)
Sendle Shipping <= n/a