PT-2026-84634 · WordPress · Wc-Vendors
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WC Vendors versions prior to 2.7.2.1
Description
An issue exists where the plugin fails to verify if the vendor submitting a front-end order shipment status change is the actual owner of the referenced order. This allows any authenticated vendor to mark orders belonging to other vendors as shipped, create order notes falsely attributed to another vendor, and trigger shipment notification emails to customers.
Recommendations
Update WC Vendors to version 2.7.2.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wc-Vendors