MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 9 h ago, last 9 h ago, peak #12

Security flaw reported in Nova Poshta WordPress shipping plugin

Original: 🚨 EUVD-2026-95707 πŸ“Š Score: 5.3/10 (CVSS v3.1) πŸ“¦ Product: Shipping for Nova Poshta 🏒 Vendor: Unknown πŸ“… Updated: 2026-10-0

A medium-severity vulnerability, EUVD-2026-95707, has been disclosed in the Shipping for Nova Poshta WordPress plugin, affecting versions through 1.19.8. The flaw, rated 5.3 out of 10 under CVSS v3.1, stems from a missing authorisation check: an AJAX action performs no nonce, authorisation or ownership verification, potentially letting unauthorised users trigger the action. Site owners using the Ukrainian delivery service's plugin are advised to watch for a patched release.

Why now: A newly published vulnerability advisory for a widely used WordPress plugin is circulating among security watchers.

Nova PoshtaShipping for Nova Poshta pluginWordPressENISA EUVD

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1606633