Impact
Colissimo Officiel : Méthodes de livraison pour WooCommerce versions up to 2.10.0 are vulnerable to Insecure Direct Object References. The flaw allows an attacker to manipulate object identifiers—such as order IDs or shipping method references—to access, modify, or delete data that belongs to another customer. This can compromise confidentiality and integrity of order information within the WooCommerce store without requiring authentication. The vulnerability is catalogued as CWE‑639, reflecting a lack of proper authorization checks when handling object references.
Affected Systems
The affected systems are WordPress installations running the Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin version 2.10.0 or older. These may be used by e‑commerce sites that rely on WooCommerce for order processing and shipping management. The plugin versions prior to 3.0.0 contain unvalidated references to order and shipping objects, creating an attack surface for unauthorized data access.
Risk and Exploitability
The CVSS score of 4.3 places this vulnerability in the medium severity range. No EPSS value is provided, so the likelihood of exploitation cannot be quantified. The ticket is not listed in CISA KEV, indicating no known widespread exploitation but still representing a valid risk for sites that process sensitive order data. Based on the description, the likely attack vector involves an external actor manipulating URLs or form parameters that reference order identifiers; the actual exploit requires access to the WooCommerce administrative interface or to a user account that can submit such requests. The inability to prevent identifier tampering can lead to theft or alteration of order details.
OpenCVE Enrichment