Junglewise Threat Intelligence

CVE-2026-57352: VillaTheme ALD Dropshipping broken authentication

CVE-2026-57352 · Severity: medium · CVSS 4.8 · Published 2026-07-02

Vendors: VillaTheme.

Executive brief

The ALD plugin for WordPress, which helps store owners manage dropshipping from AliExpress, contains a security flaw in its authentication mechanism. An unauthenticated attacker could exploit this to perform actions that should be restricted to authorized users. In some scenarios, this could lead to unauthorized access to administrative functions or site data.

Technical details

The ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin for WordPress (versions 2.2.0 and below) suffers from a broken authentication vulnerability (CWE-1390). The flaw exists in the plugin's identification and authentication logic, allowing unauthenticated remote attackers to bypass intended access controls. While the attack complexity is rated as high, successful exploitation could allow an attacker to execute functions typically reserved for higher-privileged users, potentially leading to administrative account takeover. The issue is resolved in version 2.2.1.

Affected products

  • VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0

Timeline

  • 2026-06-10: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-01: advisory: Patchstack advisory published
  • 2026-07-02: patched: NVD publication and confirmation of fix in version 2.2.1

References