Executive brief
Sendcloud Shipping is a WordPress plugin used to integrate e-commerce sites with shipping services. A security flaw in the plugin allows unauthorized individuals to bypass access controls due to missing authorization checks. This could allow an attacker to perform actions or modify settings that should be restricted to administrators, potentially disrupting shipping operations or altering order data.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Sendcloud Shipping plugin for WordPress through version 1.0.29. The flaw stems from a failure to implement proper permission checks or nonce validation on certain functions, leading to broken access control. A remote, unauthenticated attacker can exploit this by sending crafted requests to the affected site, potentially executing administrative actions or modifying plugin configurations. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.
Affected products
- Sendcloud Sendcloud Shipping n/a through 1.0.29
Timeline
- 2026-02-10: other: Vulnerability reported by researcher Nguyen Ba Khanh
- 2026-07-02: advisory: Advisory published by Patchstack and NVD