CVE-2026-16981: DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16981?
CVE-2026-16981 has a severity score of 75, indicating a high risk for potential exploitation.
How do I fix CVE-2026-16981?
To fix CVE-2026-16981, update the DHL Shipping Germany for WooCommerce plugin to version 4.0.1 or later.
What type of vulnerability is CVE-2026-16981?
CVE-2026-16981 is an unauthorized access vulnerability due to insufficient authorization checks.
Who is affected by CVE-2026-16981?
Users of the DHL Shipping Germany for WooCommerce plugin version before 4.0.1 are affected by CVE-2026-16981.
What can an attacker do with CVE-2026-16981?
An attacker can exploit CVE-2026-16981 to download shipping labels by sequentially guessing the IDs without authentication.