CVE-2026-84836: WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 3, 2026
·Updated
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
Affected Software
1 affected component
WordPress/WooCommerce Ukraine Shipping<=1.22.3
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Subscriber-level access. The attack can be performed remotely and does not require user interaction.
2
What is the potential impact if the vulnerability is exploited?
The vulnerability may expose highly sensitive information and allow limited modification of data. It does not indicate an availability impact.
3
Which plugin versions are affected?
WC Ukraine Shipping versions through 1.22.3 are identified as affected.