Executive brief
The Datalogics Ecommerce Delivery plugin for WordPress fails to properly verify user permissions, allowing authenticated users with basic subscriber access to perform sensitive operations. Attackers can create or cancel real shipping orders, modify order details, replace the store's API credentials, and send fraudulent shipping notifications to customers, potentially leading to financial loss and customer fraud.
Technical details
The plugin fails to implement proper authorization checks on sensitive endpoints, allowing authenticated users to bypass intended permission boundaries. Attackers with subscriber-level or higher privileges can invoke protected actions including order manipulation, API token modification, and order meta overwrites via the external logistics API without proper privilege escalation validation. The vulnerability affects all versions through 2.6.65.
Affected products
- Datalogics Ecommerce Delivery up to and including 2.6.65
Timeline
- 2026-09-19: disclosed