Junglewise Threat Intelligence

CVE-2026-84836: WC Ukraine Shipping IDOR in subscriber access

CVE-2026-84836 · Severity: high · CVSS 7.1 · Published 2026-09-03

Executive brief

WC Ukraine Shipping is a WordPress plugin that handles shipping configuration for online stores in Ukraine. The plugin contains an access control flaw that allows subscribers (lower-privileged users) to directly access and view data belonging to other users by manipulating URLs, potentially exposing order and customer information.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the WC Ukraine Shipping WordPress plugin affecting versions up to 1.23.0. The vulnerability allows authenticated subscribers to access sensitive data of other users by directly modifying object identifiers in URLs, bypassing proper authorization checks. The attack requires subscriber-level access to the WordPress installation but does not require admin privileges. The flaw allows exposure of sensitive shipping and order-related data. As of the advisory date, no official patch is available; users are advised to update to a version newer than 1.23.0 if available.

Affected products

  • WC Ukraine Shipping WC Ukraine Shipping <=1.23.0

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: advisory: Patchstack advisory published

References