Executive brief
A critical security flaw exists in the Datalogics Ecommerce Delivery plugin for WordPress, which manages delivery logistics for online stores. An unauthorized attacker can exploit this vulnerability to gain administrative control over the website without needing a password. This could lead to the theft of customer data, complete website takeover, or the disruption of business operations.
Technical details
The Datalogics Ecommerce Delivery plugin for WordPress (versions up to and including 2.6.62) is vulnerable to unauthenticated privilege escalation due to incorrect privilege assignment (CWE-266). The vulnerability allows a remote, unauthenticated attacker to bypass authentication mechanisms and escalate their privileges to an administrative level. This is achieved over the network without any user interaction. Successful exploitation grants the attacker full control over the WordPress environment. The issue is resolved in version 2.6.63.
Affected products
- Datalogics Datalogics Ecommerce Delivery <= 2.6.62
Timeline
- 2026-01-22: other: Vulnerability reported by researcher Jarno Vos
- 2026-04-08: advisory: Patchstack published advisory
- 2026-06-15: disclosed: CVE published to NVD
- 2026-04-08: patched: Version 2.6.63 released to address the vulnerability