Executive brief
Shiptastic for WooCommerce is a WordPress plugin used to manage shipping and logistics for online stores. A security flaw allows unauthorized individuals to potentially access sensitive information or interact with data they should not have permission to see. This could lead to the exposure of customer or order-related details, though the overall risk is currently rated as medium.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Shiptastic for WooCommerce plugin for WordPress (versions <= 5.1.0). The flaw is categorized under CWE-639, where the application fails to properly validate authorization when a user-controlled key is used to access an internal object. An unauthenticated remote attacker can exploit this by manipulating identifiers in requests to access sensitive data or perform unauthorized actions. The issue is resolved in version 5.1.1.
Affected products
- vendidero GmbH Shiptastic for WooCommerce <= 5.1.0
Timeline
- 2026-07-21: other: Reported by Guillermo Álvarez
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD
- 2026-07-23: patched: Version 5.1.1 released to address the vulnerability