Unauthenticated Broken Authentication in WooCommerce Plugin by ALD
CVE-2026-57352
4.8MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 July 2026
What is CVE-2026-57352?
The ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin has a vulnerability that allows unauthenticated users to bypass authentication. This can potentially allow malicious actors to take control over sensitive functionalities within the plugin, jeopardizing user data and the integrity of e-commerce operations. It is crucial for users of version 2.2.0 or earlier to implement security patches and updates to mitigate risks.
Affected Version(s)
ALD β Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program