Junglewise Threat Intelligence

CVE-2026-39689: eshipper eShipper Commerce missing authorization in WordPress plugin

CVE-2026-39689 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The eShipper Commerce plugin for WordPress, which integrates shipping and logistics services into online stores, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels, potentially leading to service disruptions or unauthorized actions within the shipping management system. Businesses using this plugin should update to the latest version to prevent potential interference with their commerce operations.

Technical details

A missing authorization vulnerability (CWE-862) exists in the eShipper Commerce plugin for WordPress through version 2.16.12. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before allowing access to certain functions. An unauthenticated remote attacker can exploit this to perform actions that should be restricted to higher-privileged users. According to the CVSS metrics, the primary impact is on availability. The issue is resolved in version 2.16.13.

Affected products

  • eshipper eShipper Commerce <= 2.16.12

Timeline

  • 2026-01-24: other: Vulnerability reported by researcher Legion Hunter
  • 2026-02-23: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-02-23: patched: Version 2.16.13 released to address the issue

References