Executive brief
A security vulnerability exists in the Colissimo shipping plugin for WooCommerce, which is used by online stores to manage delivery methods. An unauthorized person could potentially manipulate data or interact with the store's database by exploiting a flaw in how the plugin identifies specific objects or records. This could lead to unauthorized changes to shipping information or disruption of order processing.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress. The flaw allows an unauthenticated remote attacker to bypass authorization checks by providing a user-controlled key to access or modify internal objects. According to the CVSS vector, this can lead to low-impact integrity and availability issues, potentially allowing attackers to interact with the database or sensitive files without proper credentials. The vulnerability is addressed in version 2.10.0.
Affected products
- Colissimo Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0
Timeline
- 2026-04-29: other: Reported by HieuPenguinnn
- 2026-06-29: disclosed: Published by Patchstack and NVD
- 2026-06-29: patched: Version 2.10.0 released to address the issue