Unauthenticated Insecure Direct Object References in Colissimo Officiel for WooCommerce
CVE-2026-57341

6.5MEDIUM

What is CVE-2026-57341?

A significant security flaw exists in the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin versions 2.9.0 and earlier, which allows unauthenticated users to access sensitive data directly by manipulating URL parameters. This vulnerability can lead to unauthorized information disclosure, placing the integrity of user data at risk. Developers and website administrators utilizing this plugin should consider implementing immediate patches or alternatives to mitigate this security concern.

Affected Version(s)

Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HieuPenguinnn | Patchstack Bug Bounty Program
.