Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #12
Security flaw reported in Nova Poshta WordPress shipping plugin
Original: π¨ EUVD-2026-95707 π Score: 5.3/10 (CVSS v3.1) π¦ Product: Shipping for Nova Poshta π’ Vendor: Unknown π Updated: 2026-10-0
A medium-severity vulnerability, EUVD-2026-95707, has been disclosed in the Shipping for Nova Poshta WordPress plugin, affecting versions through 1.19.8. The flaw, rated 5.3 out of 10 under CVSS v3.1, stems from a missing authorisation check: an AJAX action performs no nonce, authorisation or ownership verification, potentially letting unauthorised users trigger the action. Site owners using the Ukrainian delivery service's plugin are advised to watch for a patched release.
Why now: A newly published vulnerability advisory for a widely used WordPress plugin is circulating among security watchers.
Nova PoshtaShipping for Nova Poshta pluginWordPressENISA EUVD
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1606633