Description
The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines 60–62 and implemented at lines 228, 263, and 291) lacking both capability checks and nonce verification, and not validating the calling user's ownership of the supplied order_id. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order item details (names, quantities, shipped counts) belonging to any customer and to modify the shipment status / shipped quantities of any order, which can also trigger order status transitions via the wxp_order_status action.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Order Modification by Authenticated Users
Action: Patch
AI Analysis

Impact

The Partial Shipment for WooCommerce plugin permits authenticated users with the Subscriber role or higher to read and modify order details of any order. Because the AJAX handlers for wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped lack capability checks and nonce verification, an attacker can trigger these actions to change shipped counts and to force order status transitions. This leads to unauthorized alterations in inventory and revenue tracking under the missing‑authorization weakness (CWE‑862).

Affected Systems

The flaw affects all installations of the wpexpertshub Partial Shipment for WooCommerce plugin version 3.4 and earlier on WordPress sites. Any site using this plugin with standard WordPress user roles conditional on the Subscriber level or above is vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1 percent signals a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access to the WordPress site and knowledge of the exposed AJAX endpoints; no privilege escalation or remote code execution is required.

Generated by OpenCVE AI on September 19, 2026 at 23:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Partial Shipment for WooCommerce plugin to the latest patched version that includes proper capability checks and nonce verification.
  • If an update cannot be applied immediately, disable or restrict the affected AJAX actions (wxp_order_shipment, wxp_order_item_shipment, wxp_order_set_shipped) so that only administrators can invoke them.
  • Introduce custom capability verification to ensure that the user owns or is permitted to modify the target order before processing any shipment changes.

Generated by OpenCVE AI on September 19, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpexpertshub
Wpexpertshub partial Shipment For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpexpertshub
Wpexpertshub partial Shipment For Woocommerce

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines 60–62 and implemented at lines 228, 263, and 291) lacking both capability checks and nonce verification, and not validating the calling user's ownership of the supplied order_id. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order item details (names, quantities, shipped counts) belonging to any customer and to modify the shipment status / shipped quantities of any order, which can also trigger order status transitions via the wxp_order_status action.
Title Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpexpertshub Partial Shipment For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-20T00:35:29.208Z

Reserved: 2026-05-28T15:55:58.558Z

Link: CVE-2026-9858

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:21.767Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:35.350

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:06Z

Weaknesses