VYPR
High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026

CVE-2026-9702

CVE-2026-9702

Description

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.