VYPR
Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026

InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking

CVE-2026-9702

Description

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.