PT-2026-67990 · WordPress · Dhl Shipping Germany
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DHL Shipping Germany for WooCommerce WordPress plugin versions prior to 4.0.1
Description
An issue exists where the shipping-label storage directory is not protected by server-independent access control, relying exclusively on an Apache .htaccess file. On web servers that do not honor .htaccess files, such as nginx, an unauthenticated visitor can download stored shipping labels containing customer names and postal addresses by requesting predictable filenames.
Recommendations
Update the plugin to version 4.0.1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhl Shipping Germany