Loading market data...
← Back to CVE feed

CVE-2026-16981

UNKNOWN View on NVD ↗

Description

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.

Published: Aug 05, 2026 07:16 UTC Modified: Aug 05, 2026 07:16 UTC