Executive brief
WC Vendors is a WordPress plugin that enables multi-vendor marketplaces by allowing vendors to manage their orders and shipments. An attacker can trick a logged-in vendor into changing the shipment status of their own orders (marking them as shipped or unshipped) by directing them to a crafted URL, causing order status confusion that may disrupt customer notifications and fulfillment operations.
Technical details
The plugin contains a cross-site request forgery (CSRF) vulnerability in its front-end order shipment status handlers (wcv_mark_shipped and wcv_mark_unshipped parameters). The handlers are triggered on page load, perform only an order-ownership check, and fail to validate CSRF tokens, allowing an attacker to forge a request that executes with the victim vendor's authentication context. The attack requires the victim to be a logged-in vendor and the attacker to know or guess a valid order ID (which are sequential and publicly visible in dashboards and customer emails). The delivery mechanism is a top-level navigation (not an embedded resource) because WordPress authentication cookies lack the SameSite attribute, defaulting to Lax behavior. The vulnerability is fixed in version 2.7.2.1.
Affected products
- WC Vendors WC Vendors before 2.7.2.1
Timeline
- 2026-08-31: disclosed
- 2026: patched: fixed in version 2.7.2.1