Webhook Manipulation in InPost PL Plugin for WordPress
CVE-2026-93580
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-93580?
The InPost PL WordPress plugin version prior to 1.9.8 is susceptible to a vulnerability where it fails to adequately verify the authenticity of incoming shipment webhook requests. The plugin relies solely on a non-secret identifier and an optional IP check, which can be easily bypassed. This oversight permits unauthenticated attackers who possess a specific order's parcel tracking number to forge the shipment status, incorrectly marking orders as completed without any legitimate authorization.
Affected Version(s)
InPost PL 1.7.5 < 1.9.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.