VYPR

DHL for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-16981Aug 5, 2026
    risk 0.00cvss epss 0.00

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and…