VYPR

InPost PL

by WordPress

CVEs (2)

  • CVE-2024-6500CriAug 17, 2024
    risk 0.65cvss 10.0epss 0.01

    The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as…

  • CVE-2026-9702HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of…