Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shiprocket: from n/a through <= 2.0.8.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shiprocket
Shiprocket shiprocket Wordpress Wordpress wordpress |
|
| Vendors & Products |
Shiprocket
Shiprocket shiprocket Wordpress Wordpress wordpress |
Fri, 20 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shiprocket: from n/a through <= 2.0.8. | |
| Title | WordPress Shiprocket plugin <= 2.0.8 - Insecure Direct Object References (IDOR) vulnerability | |
| Weaknesses | CWE-639 | |
| References |
|
Status: PUBLISHED
Assigner: Patchstack
Published: 2026-02-20T15:46:37.798Z
Updated: 2026-02-25T18:54:01.975Z
Reserved: 2025-12-15T10:01:11.953Z
Link: CVE-2025-68051
Updated: 2026-02-25T18:52:18.249Z
Status : Awaiting Analysis
Published: 2026-02-20T16:22:09.003
Modified: 2026-02-25T19:43:16.443
Link: CVE-2025-68051
No data.