Authorization Bypass in Datalogics Ecommerce Delivery Plugin for WordPress
CVE-2026-9613
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-9613?
The Datalogics Ecommerce Delivery plugin for WordPress contains an authorization bypass vulnerability that affects versions up to and including 2.6.65. This flaw occurs because the plugin fails to adequately verify user permissions before allowing actions. As a result, authenticated users with subscriber-level access can exploit this weakness to create and cancel shipping orders via the external logistics API, modify order metadata in WooCommerce, overwrite the plugin's API token, and send shipping notifications to customers, posing significant risks to e-commerce operations.
Affected Version(s)
Datalogics Ecommerce Delivery β Datalogics 0 <= 2.6.65