Executive brief
The ALD plugin for WordPress, which helps store owners manage dropshipping from AliExpress, contains a security flaw in its authentication mechanism. An unauthenticated attacker could exploit this to perform actions that should be restricted to authorized users. In some scenarios, this could lead to unauthorized access to administrative functions or site data.
Technical details
The ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin for WordPress (versions 2.2.0 and below) suffers from a broken authentication vulnerability (CWE-1390). The flaw exists in the plugin's identification and authentication logic, allowing unauthenticated remote attackers to bypass intended access controls. While the attack complexity is rated as high, successful exploitation could allow an attacker to execute functions typically reserved for higher-privileged users, potentially leading to administrative account takeover. The issue is resolved in version 2.2.1.
Affected products
- VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0
Timeline
- 2026-06-10: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-01: advisory: Patchstack advisory published
- 2026-07-02: patched: NVD publication and confirmation of fix in version 2.2.1