Missing Authorization Vulnerability in Partial Shipment Plugin for WooCommerce
CVE-2026-9858
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-9858?
The Partial Shipment for WooCommerce plugin is vulnerable to a security flaw that allows authenticated users with Subscriber-level access and above to bypass authorization mechanisms. The absence of capability checks and nonce verifications in the AJAX actions (wxp_order_shipment, wxp_order_item_shipment, wxp_order_set_shipped) can permit attackers to view sensitive order item details and alter shipment statuses. This creates a risk of unauthorized data access and potential manipulation of order details, impacting e-commerce operations significantly.
Affected Version(s)
Partial Shipment for WooCommerce 0 <= 3.4