PT-2026-67989 · WordPress · Dhl Shipping Germany
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DHL Shipping Germany for WooCommerce WordPress plugin versions prior to 4.0.1
Description
An issue exists where a shipping-label download endpoint does not perform authorization checks, such as capability, nonce, login, or ownership verification. This allows an unauthenticated attacker to use Insecure Direct Object Reference (IDOR)—a flaw where an application provides direct access to objects based on user-supplied input—to enumerate sequential ids and download stored shipping labels. These labels contain sensitive customer information, including full names, complete postal addresses, and order references.
Recommendations
Update the plugin to version 4.0.1 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhl Shipping Germany