CVE-2026-81426
Received Received - Intake

CSRF in WC Vendors WordPress Plugin

Vulnerability report for CVE-2026-81426, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wc_vendors wc_vendors to 2.7.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the WC Vendors WordPress plugin before version 2.7.2.1. It allows attackers to trick logged-in vendors into changing the shipment status of their own orders by sending a crafted request. The plugin lacks CSRF protection on certain front-end order shipment status actions.

Detection Guidance

This vulnerability can be detected by checking the installed version of the WC Vendors plugin. If the version is below 2.7.2.1, the system is vulnerable. No specific commands are provided in the context, but monitoring for unauthorized shipment status changes in vendor orders may indicate exploitation.

Impact Analysis

Attackers could exploit this to manipulate order shipment statuses without the vendor's knowledge. This could lead to incorrect order tracking, potential financial loss, or disruption of order fulfillment processes for vendors using the affected plugin version.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves CSRF on order shipment status changes in a WordPress plugin. However, unauthorized order status changes could lead to data integrity issues, which may indirectly impact compliance if order records are used for auditing or reporting under these regulations.

Mitigation Strategies

Immediately update the WC Vendors plugin to version 2.7.2.1 or later to patch the CSRF vulnerability. Ensure all users with vendor access are aware of the update and monitor for any suspicious order status changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81426. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart