PT-2026-103044 · WordPress · Inpost Pl
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
InPost PL WordPress plugin versions prior to 1.9.8
Description
The plugin fails to verify the authenticity of incoming shipment webhook requests. It relies on a non-secret identifier and an IP check that is not enforced. This allows unauthenticated attackers who possess a target order's parcel tracking number to forge the shipment status and prematurely mark the order as completed.
Recommendations
Update the InPost PL WordPress plugin to version 1.9.8 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inpost Pl