CVE-2026-9702
Description
The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | InPost PL | — | 0 < 1.9.1 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-284 Improper Access Control |