CVE-2026-9858

Published: Set 19, 2026 Last Modified: Set 21, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is due to the AJAX handlers in woocommerce-partial-shipment.php (registered at lines 60–62 and implemented at lines 228, 263, and 291) lacking both capability checks and nonce verification, and not validating the calling user's ownership of the supplied order_id. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order item details (names, quantities, shipped counts) belonging to any customer and to modify the shipment status / shipped quantities of any order, which can also trigger order status transitions via the wxp_order_status action.

862

Missing Authorization

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Access Control Availability
Potential Impacts:
Read Application Data Read Files Or Directories Modify Application Data Modify Files Or Directories Gain Privileges Or Assume Identity Bypass Protection Mechanism Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other)
Applicable Platforms
Technologies: AI/ML, Web Server, Database Server, Not Technology-Specific
View CWE Details
https://plugins.trac.wordpress.org/browser/wc-partial-shipment/tags/3.4/woocomm…
https://plugins.trac.wordpress.org/browser/wc-partial-shipment/tags/3.4/woocomm…
https://plugins.trac.wordpress.org/browser/wc-partial-shipment/tags/3.4/woocomm…
https://plugins.trac.wordpress.org/browser/wc-partial-shipment/tags/3.4/woocomm…
https://plugins.trac.wordpress.org/changeset?reponame=&old=3561104%40wc-partial…
https://www.wordfence.com/threat-intel/vulnerabilities/id/d9278c56-b963-4d9b-ae…