Medium severity5.3NVD Advisory· Published Oct 9, 2026· Updated Oct 9, 2026
CVE-2026-87846
CVE-2026-87846
Description
The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyone to delete the shipment records of arbitrary orders and to make the store issue the carrier's waybill-deletion request for those orders using the store's own stored API credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.19.8
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.