Impact
The DHL Shipping Germany for WooCommerce plugin before version 4.0.1 exposes a shipping‑label download endpoint that performs no authorization checks; an unauthenticated user can request shipping‑label URLs by ID, enumerate them, and download labels that contain sensitive customer information including full name, postal address, and order reference. This flaw results in unintended disclosure of personally identifiable information, enabling privacy violations and social‑engineering attacks.
Affected Systems
Any WordPress site running the DHL Shipping Germany for WooCommerce plugin with a version older than 4.0.1 is affected. The vulnerability is specific to the shipping‑label download functionality of this plugin.
Risk and Exploitability
Because the endpoint is reachable without authentication, the attack vector is purely remote via HTTP. The exploit requires only enumeration of sequential identifiers and the download of the resulting PDF or file. Though an EPSS score is not available, the lack of authentication combined with the sensitivity of the exposed data gives the vulnerability a high confidentiality impact. The plugin does not provide a mitigation mechanism in affected releases, and the flaw is not listed in the CISA KEV catalog, but the potential for privacy breach makes it a high‑risk issue.
OpenCVE Enrichment