CVE-2026-9235
Deferred Deferred - Pending Action

DHL eCommerce for WooCommerce Plugin Authenticated Label Deletion

Vulnerability report for CVE-2026-9235, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-09

Last updated on: 2026-07-09

Assigner: Wordfence

Description

The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hooks and act on an attacker-supplied post_id (WooCommerce order ID). This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete DHL shipping labels associated with any WooCommerce order on the site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-09
Last Modified
2026-07-09
Generated
2026-07-16
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-14
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dhl ecommerce_for_woocommerce to 2.2.3 (inc)
woocommerce dhl_ecommerce_for_woocommerce to 2.2.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Impact Analysis

This vulnerability can lead to unauthorized modification and loss of data related to DHL shipping labels in WooCommerce orders. An attacker with low-level access can manipulate shipping labels, potentially causing disruption in order fulfillment, shipping errors, or loss of important shipping information.

Executive Summary

The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress has a vulnerability in versions up to and including 2.2.3. This vulnerability arises because the plugin's create_label() and delete_label() functions lack proper capability checks and nonce verification. These functions are linked to AJAX hooks that allow actions on WooCommerce order IDs supplied by an attacker.

As a result, an authenticated attacker with Subscriber-level access or higher can create or delete DHL shipping labels for any WooCommerce order on the site without proper authorization.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9235. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart