Description
The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure
Action: Immediate Patch
AI Analysis

Impact

The Geliver Akıllı Kargo Pazaryeri WordPress plugin writes a log file that is publicly accessible. When unauthenticated users trigger requests, the log file records the site's carrier integration key and customer details from processed orders. An attacker who can read this file directly obtains the integration key, which can then be used to alter WooCommerce order statuses, potentially enabling fraudulent or misleading changes to order data. The main consequence is a loss of confidentiality for sensitive keys and customer information, and a disruption of order integrity, which could undermine customer trust and financial accuracy.

Affected Systems

This vulnerability affects the Geliver Akıllı Kargo Pazaryeri WordPress plugin versions earlier than 3.1.1. The plugin is used within WordPress sites that also host WooCommerce for e‑commerce operations. Any site that has installed one of these vulnerable plugin versions and has the plugin's log directory exposed in the web root is impacted.

Risk and Exploitability

The vulnerability is exploitable through unauthenticated HTTP access to a predictable log file location inside the web‑accessible directory of the plugin. An attacker needs only to request the file URL; no credential or additional privilege is required. The vulnerability has a CVSS score of 6.5, indicating moderate severity, and the impact is high because the disclosed data includes an API key that can be used to modify order statuses. Exploitation probability is unknown due to lack of EPSS data, but the fact that the file is world‑readable makes exploitation straightforward. The vulnerability is not listed in CISA’s KEV catalog; nonetheless its potential to disrupt e‑commerce processes warrants prompt remediation.

Generated by OpenCVE AI on October 7, 2026 at 11:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Geliver Akıllı Kargo Pazaryeri plugin to version 3.1.1 or later, which removes the public log file exposure.
  • If an immediate upgrade is not possible, relocate the log file outside the web‑root or restrict its permissions so that it is no longer accessible via HTTP.
  • Delete any existing log file that contains the carrier integration key and customer data to remove the stored secrets.
  • Verify that only authorized administrators can modify WooCommerce order statuses, and configure the store to log order state changes securely.

Generated by OpenCVE AI on October 7, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed.
Title Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log File
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T10:09:58.493Z

Reserved: 2026-09-30T13:08:19.855Z

Link: CVE-2026-103378

cve-icon Vulnrichment

Updated: 2026-10-07T09:59:29.991Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.160

Modified: 2026-10-07T11:17:09.163

Link: CVE-2026-103378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T12:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor