Executive brief
The Partial Shipment for WooCommerce plugin for WordPress lacks proper access controls on shipment management features. Attackers with basic user accounts can read order details belonging to any customer and modify shipment statuses across the entire store, potentially disrupting fulfillment processes and exposing sensitive customer information.
Technical details
The plugin's AJAX handlers (wxp_order_shipment, wxp_order_item_shipment, wxp_order_set_shipped) in woocommerce-partial-shipment.php lack capability checks, nonce verification, and order ownership validation. Authenticated Subscriber-level users can exploit this to read arbitrary order item details and modify shipment quantities and status transitions via the wxp_order_status action.
Affected products
- WooCommerce/WordPress Partial Shipment for WooCommerce up to and including 3.4
Timeline
- 2026-09-19: disclosed