Authorization Bypass in Datalogics Ecommerce Delivery Plugin for WordPress
CVE-2026-9613

4.3MEDIUM

What is CVE-2026-9613?

The Datalogics Ecommerce Delivery plugin for WordPress contains an authorization bypass vulnerability that affects versions up to and including 2.6.65. This flaw occurs because the plugin fails to adequately verify user permissions before allowing actions. As a result, authenticated users with subscriber-level access can exploit this weakness to create and cancel shipping orders via the external logistics API, modify order metadata in WooCommerce, overwrite the plugin's API token, and send shipping notifications to customers, posing significant risks to e-commerce operations.

Affected Version(s)

Datalogics Ecommerce Delivery – Datalogics 0 <= 2.6.65

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Benedictus Jovan (aillesiM)
.