PT-2026-95809 · WordPress · Partial Shipment For Woocommerce

·

CVE-2026-9858

·

Published

2026-09-19

·

Updated

2026-09-20

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Partial Shipment for Woocommerce versions prior to 3.5
Description Missing authorization in the plugin allows authenticated users with Subscriber-level access and above to access and modify order data. The issue exists within the woocommerce-partial-shipment.php file due to a lack of capability checks, nonce verification, and failure to validate if the calling user owns the supplied order id. Attackers can read arbitrary order item details, such as names, quantities, and shipped counts, and modify shipment status or shipped quantities. This can also trigger order status transitions via the wxp order status action. The affected AJAX actions are 'wxp order shipment', 'wxp order item shipment', and 'wxp order set shipped'.
Recommendations Update Partial Shipment for Woocommerce to version 3.5 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9858

Affected Products

Partial Shipment For Woocommerce