WordPress Plugin Vulnerabilities

DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR

Description

The plugin does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.

Proof of Concept

Affects Plugins

Fixed in 4.0.1

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Pedro Pinho, Artus KG
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 9 days ago)
Added
2026-08-04 (about 18 hours ago)
Last Updated
2026-08-04 (about 18 hours ago)

Other