CVE-2026-103685: WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 2.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerceto a version that resolves this vulnerability.Fixed in 2.2.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access and low-privileged access to the affected WordPress site. No user interaction is required.
What is the potential impact?
The vulnerability can affect integrity, with a CVSS vector indicating low impact to integrity and no identified confidentiality or availability impact.
Which plugin versions are affected?
ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce versions through 2.2.4 are affected. The provided data does not identify a fixed version.