WordPress Plugin Vulnerabilities

WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change

Description

The plugin does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.

Proof of Concept

Affects Plugins

Fixed in 2.7.2.1

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Bhaveshkumar Parmar
Submitter
Bhaveshkumar Parmar
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other