rootpwn

medium · CVSS v3 4.3 · EPSS 0.00343

CVE-2026-9613

The Datalogics Ecommerce Delivery plugin for WordPress up to version 2.6.65 contains an authorization bypass vulnerability. It allows authen

Overview

The Datalogics Ecommerce Delivery plugin for WordPress up to version 2.6.65 contains an authorization bypass vulnerability. It allows authenticated users with subscriber-level access to manipulate shipping orders, modify WooCommerce order metadata, and alter API tokens via the external logistics API. This matters because it compromises e-commerce integrity and customer communication channels.

Description

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.

Impact

The vulnerability impacts the confidentiality, integrity, and availability of the e-commerce platform. Authenticated attackers with minimal privileges can manipulate shipping orders, alter sensitive order metadata, and abuse stored API tokens. Store administrators and customers are directly impacted through potential financial discrepancies, unauthorized API usage, and fraudulent notification emails. The CIA triad is affected primarily through loss of integrity and unauthorized actions.

Remediation

Update the Datalogics Ecommerce Delivery plugin to a version later than 2.6.65 as soon as a patched release becomes available. Audit existing WooCommerce order metadata and shipping logs for unauthorized modifications. Review plugin permissions and restrict subscriber-level access where possible.

Risk context

The vulnerability carries a medium severity rating with a CVSS v3 score of 4.3. The EPSS value of 0.00343 indicates a relatively low current likelihood of exploitation in the wild, but active monitoring is recommended due to the potential for business logic abuse.

Affected products

  • Datalogics Ecommerce Delivery plugin for WordPress

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
EPSS
0.00343

WordPress WooCommerce Authorization Bypass Plugin API Abuse

← All CVEs