Junglewise Threat Intelligence

CVE-2026-65536: Mahdi Yousefi Persian WooCommerce Shipping CSRF

CVE-2026-65536 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

A vulnerability exists in a popular Iranian shipping plugin for WooCommerce, which handles postal and courier delivery options. An attacker could trick a site administrator into performing unintended actions, such as changing shipping settings or modifying order details, by getting them to click a malicious link. This could disrupt delivery operations or lead to unauthorized changes in how shipping costs are calculated.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Persian WooCommerce Shipping plugin (persian-woocommerce-shipping) for WordPress in versions up to and including 4.4.5. The flaw is due to missing nonce validation on sensitive administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious web page or link and tricking a site administrator into interacting with it while authenticated. Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the targeted user, such as modifying plugin configurations. As of the advisory date, no official patch has been released.

Affected products

  • Mahdi Yousefi افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) (Persian WooCommerce Shipping) <= 4.4.5

Timeline

  • 2026-06-12: other: Vulnerability reported by researcher Ananda Dhakal
  • 2026-07-23: disclosed: Advisory published by Patchstack and NVD

References