plugin

Dhl For Woocommerce Vulnerabilities

2 known security issues reported for the Dhl For Woocommerce WordPress plugin. Most recent disclosed Jul 27, 2026.

2 medium

Running Dhl For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

DHL for WooCommerce <= 4.0.0 - Insecure Direct Object Reference to Unauthenticated Shipping Label Download

medium

The DHL for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0. This is due to shipping label files stored at predictable, publicly accessible upload paths and old-style labels returning a direct public URL that bypassed the capability-checked down...

CVSS:
5.3
Affected:
up to 4.0.0
Fixed in:
4.0.1
Disclosed:
Jul 27, 2026

CVE-2026-16981 on NVD →

DHL for WooCommerce <= 4.0.0 - Unauthenticated Shipping Label Disclosure

medium

The DHL for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.0.0. This is due to shipping label files stored in a predictable, publicly accessible uploads subdirectory without an unguessable path component, combined with a fallback code path that retur...

CVSS:
5.3
Affected:
up to 4.0.0
Fixed in:
4.0.1
Disclosed:
Jul 27, 2026

CVE-2026-16993 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database