Impact
The Datalogics Ecommerce Delivery plugin for WordPress is vulnerable because it does not verify that a user is authorized to perform several AJAX actions. This oversight allows any authenticated user with a subscriber role or higher to create and cancel real shipping orders via the external logistics API, alter WooCommerce order metadata on any order, overwrite the plugin’s stored API token, and trigger shipping notification emails to customers. Consequently, an attacker can manipulate shipping processes, tamper with order data, and disrupt customer communication, compromising data integrity and potentially causing financial or reputational harm.
Affected Systems
The vulnerability affects any WordPress installation running the Datalogics Ecommerce Delivery plugin version 2.6.65 or earlier. Site owners using these versions should verify that the plugin is either upgraded or removed.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is below 1 %, suggesting a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector requires only a valid WordPress account with subscriber-level access, which is common on many sites, so the risk to affected deployments is moderate at best. Exploitation proceeds by accessing the publicly exposed AJAX endpoints that perform shipping operations without proper authorization checks. If an attacker manages to acquire sufficient privileges, they can compromise order integrity and trigger unwanted notifications.
OpenCVE Enrichment