Impact
The vulnerability resides in the InPost for WooCommerce plugin where incoming shipment webhook requests are not properly authenticated. The plugin accepts a non‑secret identifier and does not enforce an IP check, allowing attackers to submit a forged request if they know the parcel tracking number. A forged request can change the order status to completed prematurely, potentially enabling fraud or revenue loss. This flaw permits an attacker to modify transaction state without authentication, bypassing normal workflow controls.
Affected Systems
Vendors: InPost PL; Product: InPost for WooCommerce plugin used in WordPress. Versions affected are 1.7.5 through 1.9.7, inclusive. The issue does not exist in 1.9.8 or later, where authentication of the webhook is properly implemented.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation but still a significant risk due to the nature of the flaw. Attackers only need knowledge of a valid tracking number and can send a crafted request from any IP address, as the IP restriction is not enforced. Because the flaw directly changes order status, it has a high severity impact on integrity and availability of e‑commerce operations. The lack of authentication makes the attack path simple and likely to be exploited in a targeted attack scenario.
OpenCVE Enrichment