VYPR
Medium severity4.3NVD Advisory· Published Jan 23, 2026· Updated Apr 28, 2026

CVE-2026-24571

CVE-2026-24571

Description

Missing Authorization vulnerability in boxnow BOX NOW Delivery box-now-delivery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BOX NOW Delivery: from n/a through <= 3.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in BOX NOW Delivery plugin (≤3.0.2) allows unauthenticated attackers to exploit access control flaws.

Vulnerability

Overview

The BOX NOW Delivery WordPress plugin versions up to and earlier contain a missing authorization vulnerability. The plugin fails to properly enforce access control checks on certain functions, allowing an attacker to exploit incorrectly configured security levels. This broken access control issue means that unauthenticated or low-privileged users can perform actions that should require higher privileges [1].

Exploitation

Attackers can exploit this vulnerability without needing no authentication or special network position. The missing authorization check means that any request to the vulnerable endpoint is processed without verifying the user's permissions. This type of flaw is commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously [1].

Impact

Successful exploitation allows an attacker to execute higher-privileged actions, potentially leading to unauthorized data access or modification. The CVSS v3 base score is 4.3 (Medium), indicating a moderate severity. The vulnerability is considered low impact and unlikely to be exploited in targeted attacks, but the ease of exploitation makes it attractive for automated scanning [1].

Mitigation

The vendor has released version 3.2.0 which resolves the issue. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is the only reliable mitigation [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.