The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 25 Jun 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 |
Thu, 25 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site. | |
| Title | InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-25T12:35:25.054Z
Reserved: 2026-05-27T12:27:44.505Z
Link: CVE-2026-9702
Updated: 2026-06-25T12:33:39.960Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T07:30:17Z