Junglewise Threat Intelligence

CVE-2026-9235: DHL eCommerce (Benelux) for WooCommerce missing authorization in label management

CVE-2026-9235 · Severity: medium · CVSS 4.3 · Published 2026-07-09

Executive brief

The DHL eCommerce plugin for WooCommerce, which manages shipping labels for online stores, contains a security flaw that allows unauthorized users to modify shipping data. An attacker with a basic customer account could create or delete shipping labels for any order on the site, not just their own. This could lead to fraudulent shipping activity, loss of label data, and disruption of order fulfillment operations.

Technical details

The vulnerability is classified as Missing Authorization (CWE-862) and Cross-Site Request Forgery (CSRF) due to missing capability checks and nonce verification in the `create_label()` and `delete_label()` functions. These functions are exposed via the `wp_ajax_dhlpwc_label_create` and `wp_ajax_dhlpwc_label_delete` hooks. An authenticated attacker with Subscriber-level permissions or higher can send crafted AJAX requests with a targeted `post_id` (WooCommerce order ID) to manipulate DHL shipping labels across the entire platform. The issue affects all versions up to and including 2.2.3; a patch was introduced in subsequent updates.

Affected products

  • dhlparcel DHL eCommerce (Benelux) for WooCommerce up to, and including, 2.2.3

Timeline

  • 2026-07-09: advisory: Initial disclosure by Wordfence and NVD publication

References