Description
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
Published: 2026-06-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated IDOR that allows an attacker to access or modify resources they should not be able to reach. The flaw arises from insufficient checks on user‑supplied identifiers, permitting read/write of shipping details or other sensitive data related to the WooCommerce plugin. As a result, an attacker can obtain private information about customers or alter order details, compromising confidentiality and integrity.

Affected Systems

The affected product is the WordPress plugin 'Colissimo Officiel : Méthodes de livraison pour WooCommerce', versions 2.9.0 and earlier. Any site running these versions on WordPress may be impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, and the lack of an EPSS score or KEV listing suggests no current public exploitation. The flaw is unauthenticated, meaning exploitation does not require a known account and can be performed by any user who can reach the plugin's endpoints. Attackers could target the public‑facing shop or attempt brute‑force requests to discover valid identifiers. The overall risk is moderate, but mitigation is recommended promptly.

Generated by OpenCVE AI on June 29, 2026 at 16:35 UTC.

Remediation

Vendor Solution

Update the WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin to the latest available version (at least 2.10.0).


OpenCVE Recommended Actions

  • Apply the vendor patch and upgrade the plugin to version 2.10.0 or later.
  • If immediate upgrade is not possible, block unauthorized access to the plugin's administrative URLs using a firewall or web‑application firewall.
  • Monitor access logs for suspicious IDOR attempts and review order data for unauthorized changes.

Generated by OpenCVE AI on June 29, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Colissimo
Colissimo colissimo Officiel : Méthodes De Livraison Pour Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Colissimo
Colissimo colissimo Officiel : Méthodes De Livraison Pour Woocommerce
Wordpress
Wordpress wordpress

Mon, 29 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
Title WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.9.0 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Colissimo Colissimo Officiel : Méthodes De Livraison Pour Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T10:22:54.867Z

Reserved: 2026-06-24T12:45:19.179Z

Link: CVE-2026-57341

cve-icon Vulnrichment

Updated: 2026-07-01T10:22:52.023Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:04:27Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key