Unauthenticated Insecure Direct Object References in Colissimo Officiel for WooCommerce
CVE-2026-57341
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 June 2026
What is CVE-2026-57341?
A significant security flaw exists in the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin versions 2.9.0 and earlier, which allows unauthenticated users to access sensitive data directly by manipulating URL parameters. This vulnerability can lead to unauthorized information disclosure, placing the integrity of user data at risk. Developers and website administrators utilizing this plugin should consider implementing immediate patches or alternatives to mitigate this security concern.
Affected Version(s)
Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0