Description
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Modification
Action: Apply Patch
AI Analysis

Impact

The Datalogics Ecommerce Delivery plugin for WordPress is vulnerable because it does not verify that a user is authorized to perform several AJAX actions. This oversight allows any authenticated user with a subscriber role or higher to create and cancel real shipping orders via the external logistics API, alter WooCommerce order metadata on any order, overwrite the plugin’s stored API token, and trigger shipping notification emails to customers. Consequently, an attacker can manipulate shipping processes, tamper with order data, and disrupt customer communication, compromising data integrity and potentially causing financial or reputational harm.

Affected Systems

The vulnerability affects any WordPress installation running the Datalogics Ecommerce Delivery plugin version 2.6.65 or earlier. Site owners using these versions should verify that the plugin is either upgraded or removed.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score is below 1 %, suggesting a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector requires only a valid WordPress account with subscriber-level access, which is common on many sites, so the risk to affected deployments is moderate at best. Exploitation proceeds by accessing the publicly exposed AJAX endpoints that perform shipping operations without proper authorization checks. If an attacker manages to acquire sufficient privileges, they can compromise order integrity and trigger unwanted notifications.

Generated by OpenCVE AI on September 19, 2026 at 23:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Datalogics Ecommerce Delivery plugin to the latest available version (≥ 2.6.66) to eliminate the authorization bypass.
  • Restrict the permissions granted to the WordPress subscriber role so that it cannot access the AJAX endpoints used for shipping and order modification, or remove those capabilities from the role entirely.
  • If an immediate upgrade is not possible, temporarily disable the plugin’s AJAX shipping actions or block the related endpoints using a web‑application firewall or code changes, and closely monitor logs for any unauthorized shipping activity.

Generated by OpenCVE AI on September 19, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L198 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L244 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L5 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L646 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L679 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L691 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L76 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L809 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L198 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L244 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L5 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L646 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L679 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L691 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L76 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L809 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3552733%40datalogics&new=3552733%40datalogics cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed27b8-dbdc-4927-8019-52a622bfbff6?source=cve cve-icon cve-icon
History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Datalogics
Datalogics datalogics Ecommerce Delivery – Datalogics
Wordpress
Wordpress wordpress
Vendors & Products Datalogics
Datalogics datalogics Ecommerce Delivery – Datalogics
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.
Title Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Datalogics Datalogics Ecommerce Delivery – Datalogics
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:18.728Z

Reserved: 2026-05-26T16:29:51.747Z

Link: CVE-2026-9613

cve-icon Vulnrichment

Updated: 2026-09-19T13:48:21.944Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:35.060

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:08Z

Weaknesses