Description
The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized order completion via forged shipment status
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the InPost for WooCommerce plugin where incoming shipment webhook requests are not properly authenticated. The plugin accepts a non‑secret identifier and does not enforce an IP check, allowing attackers to submit a forged request if they know the parcel tracking number. A forged request can change the order status to completed prematurely, potentially enabling fraud or revenue loss. This flaw permits an attacker to modify transaction state without authentication, bypassing normal workflow controls.

Affected Systems

Vendors: InPost PL; Product: InPost for WooCommerce plugin used in WordPress. Versions affected are 1.7.5 through 1.9.7, inclusive. The issue does not exist in 1.9.8 or later, where authentication of the webhook is properly implemented.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation but still a significant risk due to the nature of the flaw. Attackers only need knowledge of a valid tracking number and can send a crafted request from any IP address, as the IP restriction is not enforced. Because the flaw directly changes order status, it has a high severity impact on integrity and availability of e‑commerce operations. The lack of authentication makes the attack path simple and likely to be exploited in a targeted attack scenario.

Generated by OpenCVE AI on September 30, 2026 at 12:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade InPost for WooCommerce to version 1.9.8 or later to obtain the fixed webhook authentication logic.
  • If an upgrade is not immediately possible, block the shipment webhook endpoint from all external IPs and allow only traffic from the official InPost webhook IP ranges.
  • Implement an additional layer of verification by adding a secret token or shared key to the webhook payload and validate it on the server before processing shipment status changes.
  • Audit current orders to ensure none have been prematurely marked complete, and consider resetting any orders that appear suspicious.

Generated by OpenCVE AI on September 30, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 30 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.
Title InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-30T06:00:25.490Z

Reserved: 2026-09-18T10:48:05.277Z

Link: CVE-2026-93580

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T06:17:10.160

Modified: 2026-09-30T06:17:10.160

Link: CVE-2026-93580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses