PT-2026-56788 · WordPress · Dhl Ecommerce (Benelux) For Woocommerce
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DHL eCommerce (Benelux) for WooCommerce versions prior to 2.2.4
Description
The plugin is susceptible to unauthorized data modification and loss. This occurs because the
create label() and delete label() functions lack proper capability checks and nonce verification. These functions are linked to the wp ajax dhlpwc label create and wp ajax dhlpwc label delete hooks and process an attacker-supplied post id variable, which represents a WooCommerce order ID. Consequently, authenticated users with Subscriber-level permissions or higher can create or delete DHL shipping labels for any WooCommerce order on the site.Recommendations
Update the plugin to a version newer than 2.2.3.
As a temporary mitigation, restrict access to the
create label() and delete label() functions for users with Subscriber-level permissions.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhl Ecommerce (Benelux) For Woocommerce