Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Jul 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iscpcolissimo
Iscpcolissimo colissimo Shipping Methods For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Iscpcolissimo
Iscpcolissimo colissimo Shipping Methods For Woocommerce Wordpress Wordpress wordpress |
Thu, 09 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Jul 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, and including, 2.9.0. This is due to the handler performing no current_user_can() capability check and no nonce verification before reading an attacker-supplied order_id and modifying that order's shipping method, pickup-point meta, and shipping address. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or modify the shipment information (shipping method, pickup relay data, and shipping address) of arbitrary WooCommerce orders, including orders placed by other users. | |
| Title | Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-09T14:37:58.884Z
Reserved: 2026-05-21T18:54:54.933Z
Link: CVE-2026-9240
Updated: 2026-07-09T14:37:54.860Z
Status : Deferred
Published: 2026-07-09T11:16:42.483
Modified: 2026-07-09T16:19:45.567
Link: CVE-2026-9240
No data.
OpenCVE Enrichment
Updated: 2026-07-31T13:30:17Z