Executive brief
The Colissimo shipping plugin for WooCommerce provides delivery method integration for online stores. A vulnerability in versions 2.10.0 and earlier allows attackers to manipulate order or customer identifiers in URLs to view or access other customers' shipping and order data, potentially exposing sensitive transaction information.
Technical details
This is an Insecure Direct Object Reference (IDOR) vulnerability in the Colissimo Officiel plugin for WooCommerce (versions ≤ 2.10.0). The vulnerability allows attackers to bypass access controls by modifying object identifiers (such as order IDs or customer IDs) in URLs or API requests. An authenticated customer or unauthenticated attacker can enumerate and access other users' shipping and order data without proper authorization checks. The vulnerable component fails to validate that the requesting user owns or has permission to access the referenced objects. The patch is available in version 3.0.0.
Affected products
- La Poste Colissimo Officiel : Méthodes de livraison pour WooCommerce ≤ 2.10.0
Timeline
- 2026-07-29: disclosed: Reported to Patchstack by TurboNexic
- 2026-08-06: patched: Fixed in version 3.0.0
- 2026-08-06: advisory: Published as CVE-2026-66692