InPost PL <= 1.9.0 - Missing Authorization to Unauthenticated WooCommerce Order Parcel-Locker Hijacking
medium
The InPost PL plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.9.0. This is due to missing order ownership verification in the update_locker_from_typ_page AJAX handler, which did not validate the order key before updating order meta. This makes it possible for unauthenticate...
- CVSS:
- 5.3
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.1
- Disclosed:
- Jun 4, 2026
CVE-2026-9702 on NVD →
InPost for WooCommerce <= 1.4.0 and InPost PL <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary File Read and Delete
critical
The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as 1.4.4 (for InPost PL). This makes it possi...
- CVSS:
- 10
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Aug 16, 2024
CVE-2024-6500 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database