CVE-2026-16993
Received Received - Intake

DHL Shipping Germany for WooCommerce Plugin Sensitive File Exposure

Vulnerability report for CVE-2026-16993, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
artus_kg dhl_for_woocommerce to 4.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the DHL Shipping Germany for WooCommerce WordPress plugin before version 4.0.1. It stores shipping labels in a directory that only uses an Apache .htaccess file for access control. On servers like nginx that ignore .htaccess rules, unauthenticated users can download these labels by guessing predictable filenames, exposing customer names and postal addresses.

Detection Guidance

Check if the DHL Shipping Germany for WooCommerce plugin version is below 4.0.1. Inspect the plugin's shipping-label storage directory for exposed files by attempting to access predictable filenames directly via URL.

Impact Analysis

If you use the vulnerable plugin version, attackers could access and download shipping labels containing customer names and postal addresses. This could lead to privacy breaches, identity theft, or misuse of personal data. The impact depends on whether your server uses Apache or another web server like nginx.

Compliance Impact

This vulnerability likely violates GDPR and other privacy regulations by exposing personal data (names and addresses) without proper protection. Organizations could face fines or legal consequences for failing to secure customer data adequately.

Mitigation Strategies

Update the DHL Shipping Germany for WooCommerce plugin to version 4.0.1 or later immediately. Ensure your web server enforces proper access controls for sensitive directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16993. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart