Standard Box Sizes – for WooCommerce
Standard Box Sizes – for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Standard Box Sizes – for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Kévin Mosbahi (Mika). Standard Box Sizes – for WooCommerce is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-22318Standard Box Sizes – for WooCommerce <= 1.6.13 - Missing Authorization
Read the full analysisVulnerability Records

Standard Box Sizes – for WooCommerce
Author
enituretechnology
The Standard Box Sizes plugin is designed exclusively for use with Eniture Technology’s Small Package Quotes plugins. The plugin allows merchants to record standard box sizes which are subsequently used to identify a packaging solution prior to obtaining shipping rate estimates. The packaging solution is saved with orders as a step-by-step graphical illustration that the merchant can refer to during fulfillment. The result is the most accurate shipping rate estimates possible. The Small Package Quotes plugin is available for FedEx, Purolator, UPS, and UPS reseller Worldwide Express. Key Features Define standard box sizes. Automate the identification of the most efficient packaging solution. Refer to a step-by-step graphical illustration of the packaging solution during fulfillment. Record the weight of each box so the weight of the packaging solution is precise. Specify the maximum weight capacity of each box. Stipulate whether individual products can be rotated for placement in a box. Identify which products ship as their own package and should not be boxed with other items. Requirements WooCommerce 6.4 or newer. The installation of at least one of Eniture Technology’s Small Package Quotes plugins.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C