Executive brief
A WooCommerce plugin for Hungarian pickup points and shipping labels fails to properly restrict access to sensitive functions and data. Unauthenticated attackers can bypass access controls to view or manipulate shipping information and package point data that should be restricted to authorized users only, potentially disrupting order fulfillment and exposing customer information.
Technical details
This is a broken access control vulnerability in the WordPress plugin "Csomagpontok és szállítási címkék WooCommerce-hez" (versions before 4.2.8) where authorization checks are missing or incorrectly implemented. The vulnerability allows unauthenticated attackers to access pages or perform actions they should not be permitted to execute, affecting shipping label and pickup point management functionality. No authentication is required to exploit this issue; an attacker can send requests directly to the vulnerable endpoints. The exploit enables unauthorized access to package and shipping data, potentially leading to order manipulation or information disclosure. The fix is available in version 4.2.8 and later.
Affected products
- Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez before 4.2.8
Timeline
- 2026-09-08: disclosed: Vulnerability published on NVD
- 2026-09-07: patched: Fix released in version 4.2.8