Colissimo shipping methods for WooCommerce <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting
high
The Colissimo shipping methods for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 7.2
- Affected:
- up to 2.10.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 10, 2026
CVE-2026-66697 on NVD →
Colissimo shipping methods for WooCommerce <= 2.10.0 - Authenticated (Customer+) Insecure Direct Object Reference
medium
The Colissimo shipping methods for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.10.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with customer-level access and above, to perform an unaut...
- CVSS:
- 4.3
- Affected:
- up to 2.10.0
- Fixed in:
- 3.0.0
- Disclosed:
- Jul 29, 2026
CVE-2026-66692 on NVD →
Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action
medium
The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, and including, 2.9.0. This is due t...
- CVSS:
- 4.3
- Affected:
- up to 2.9.0
- Fixed in:
- 2.10.0
- Disclosed:
- Jul 8, 2026
CVE-2026-9240 on NVD →
Colissimo shipping methods for WooCommerce <= 2.9.0 - Unauthenticated Insecure Direct Object Reference
medium
The Colissimo shipping methods for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.9.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.9.0
- Fixed in:
- 2.10.0
- Disclosed:
- Jun 29, 2026
CVE-2026-57341 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database