Description
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WC Vendors WordPress plugin prior to version 2.7.2.1 allows an authenticated vendor to change the shipment status of any order without verifying ownership of that order. This can result in the order being marked as shipped, an order note being added falsely attributed to the victim vendor, and the customer receiving a shipment notification email that was not actually sent by the vendor. The flaw represents a classic access control weakness in a multi‑tenant marketplace environment, effectively permitting one vendor to manipulate another vendor's transaction state and mislead end customers.

Affected Systems

Any WordPress site that installs the WC Vendors plugin with a version older than 2.7.2.1 is susceptible. Site administrators should identify installations of WC Vendors and confirm the current plugin version, ensuring it is updated to at least 2.7.2.1 or later.

Risk and Exploitability

Although no CVSS score is published and EPSS information is missing, the flaw is of high concern because it requires only that the attacker be an authenticated vendor, a role that is likely widely available on the platform. The attacker can tamper with orders from any vendor, potentially causing financial loss, reputational damage, and customer dissatisfaction. The vulnerability is not listed in CISA’s KEV catalog, but the impact and ease of exploitation warrant proactive remediation. There is no known public exploit, yet the verification step is trivial for a privileged user.

Generated by OpenCVE AI on September 2, 2026 at 07:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WC Vendors plugin to version 2.7.2.1 or later
  • Audit existing orders to detect and correct any unauthorized shipment status changes or false vendor notes
  • Enforce or reconfigure access controls so that vendors can modify only orders they own, for example by adjusting role capabilities or plugin settings

Generated by OpenCVE AI on September 2, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
Title WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T06:00:22.635Z

Reserved: 2026-08-26T19:11:49.129Z

Link: CVE-2026-81427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T06:17:19.280

Modified: 2026-09-02T06:17:19.280

Link: CVE-2026-81427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T08:00:14Z

Weaknesses