High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
CVE-2026-9702
CVE-2026-9702
Description
The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.