Junglewise Threat Intelligence

CVE-2026-66692: Colissimo Officiel Méthodes de livraison WooCommerce IDOR

CVE-2026-66692 · Severity: medium · CVSS 4.3 · Published 2026-08-06

Technologies: La Poste Colissimo Officiel : Méthodes de livraison pour WooCommerce.

Executive brief

The Colissimo shipping plugin for WooCommerce provides delivery method integration for online stores. A vulnerability in versions 2.10.0 and earlier allows attackers to manipulate order or customer identifiers in URLs to view or access other customers' shipping and order data, potentially exposing sensitive transaction information.

Technical details

This is an Insecure Direct Object Reference (IDOR) vulnerability in the Colissimo Officiel plugin for WooCommerce (versions ≤ 2.10.0). The vulnerability allows attackers to bypass access controls by modifying object identifiers (such as order IDs or customer IDs) in URLs or API requests. An authenticated customer or unauthenticated attacker can enumerate and access other users' shipping and order data without proper authorization checks. The vulnerable component fails to validate that the requesting user owns or has permission to access the referenced objects. The patch is available in version 3.0.0.

Affected products

  • La Poste Colissimo Officiel : Méthodes de livraison pour WooCommerce ≤ 2.10.0

Timeline

  • 2026-07-29: disclosed: Reported to Patchstack by TurboNexic
  • 2026-08-06: patched: Fixed in version 3.0.0
  • 2026-08-06: advisory: Published as CVE-2026-66692

References