GHSA-xqqx-fcgc-wmxpMediumCVSS 5.3

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any...

Published
August 5, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.

🔗 References (3)