Executive brief
A security vulnerability exists in the WooCommerce Dropshipping plugin, which is used by online stores to manage supplier orders and inventory. An unauthenticated attacker can bypass security checks to perform actions that should be restricted to administrators. This could lead to unauthorized access to the website's management interface, potentially compromising customer data or store operations.
Technical details
The WooCommerce Dropshipping plugin for WordPress (versions up to and including 5.2.4) contains a broken authentication vulnerability (CWE-288). The flaw allows an unauthenticated remote attacker to bypass authentication mechanisms via an alternate path or channel. By exploiting this vulnerability, a malicious actor can perform actions typically reserved for high-privileged users, which may lead to full administrative takeover of the WordPress site. The issue is addressed in version 5.2.5.
Affected products
- OPMC WooCommerce Dropshipping <= 5.2.4
Timeline
- 2026-04-20: other: Reported by Nguyen Ba Khanh
- 2026-06-08: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date
- 2026-06-17: patched: Patch confirmed available in version 5.2.5