The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inpost Pl
Inpost Pl inpost Pl Wordpress Wordpress wordpress |
|
| Vendors & Products |
Inpost Pl
Inpost Pl inpost Pl Wordpress Wordpress wordpress |
Thu, 25 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Thu, 25 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 |
Thu, 25 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 25 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 |
Thu, 25 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site. | |
| Title | InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-06-25T06:00:02.239Z
Updated: 2026-06-25T12:35:25.054Z
Reserved: 2026-05-27T12:27:44.505Z
Link: CVE-2026-9702
Updated: 2026-06-25T12:33:39.960Z
No data.
No data.