Junglewise Threat Intelligence

CVE-2026-81426: WC Vendors WordPress plugin CSRF in order shipment status

CVE-2026-81426 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Technologies: WC Vendors. Vendors: WC Vendors.

Executive brief

WC Vendors is a WordPress plugin that enables multi-vendor marketplaces by allowing vendors to manage their orders and shipments. An attacker can trick a logged-in vendor into changing the shipment status of their own orders (marking them as shipped or unshipped) by directing them to a crafted URL, causing order status confusion that may disrupt customer notifications and fulfillment operations.

Technical details

The plugin contains a cross-site request forgery (CSRF) vulnerability in its front-end order shipment status handlers (wcv_mark_shipped and wcv_mark_unshipped parameters). The handlers are triggered on page load, perform only an order-ownership check, and fail to validate CSRF tokens, allowing an attacker to forge a request that executes with the victim vendor's authentication context. The attack requires the victim to be a logged-in vendor and the attacker to know or guess a valid order ID (which are sequential and publicly visible in dashboards and customer emails). The delivery mechanism is a top-level navigation (not an embedded resource) because WordPress authentication cookies lack the SameSite attribute, defaulting to Lax behavior. The vulnerability is fixed in version 2.7.2.1.

Affected products

  • WC Vendors WC Vendors before 2.7.2.1

Timeline

  • 2026-08-31: disclosed
  • 2026: patched: fixed in version 2.7.2.1

References

Related threats