Junglewise Threat Intelligence

CVE-2026-8678: MyParcel WordPress plugin authorization bypass in shipment options

CVE-2026-8678 · Severity: medium · CVSS 4.3 · Published 2026-07-11

Executive brief

The MyParcel plugin for WordPress, which integrates shipping services with online stores, contains a security flaw that allows low-level users to bypass authorization. An attacker with a basic account (such as a customer) could view or change shipping details for any order on the site. This includes modifying the carrier, package type, weight, and insurance settings, potentially disrupting logistics and causing financial discrepancies.

Technical details

The MyParcel plugin for WordPress (specifically the WooCommerce integration) suffers from a missing authorization check (CWE-862) in the class-wcmypa-admin.php component. The plugin fails to properly verify user permissions before allowing actions related to shipment management. An authenticated attacker with subscriber-level privileges or higher can exploit this over the network to view or modify shipment metadata, including carrier selection, delivery types, package specifications, and insurance requirements for any order ID. The vulnerability is present in all versions up to 4.25.1.

Affected products

  • richardperdaan MyParcel (WooCommerce) up to, and including, 4.25.1

Timeline

  • 2026-07-11: disclosed
  • 2026-07-11: advisory

References