CVE-2026-81427
Received Received - Intake

WC Vendors Order Shipment Manipulation Vulnerability

Vulnerability report for CVE-2026-81427, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wc_vendors wc_vendors to 2.7.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a broken access control flaw in the WC Vendors WordPress plugin before version 2.7.2.1. It allows any authenticated vendor to change the shipment status of another vendor's order without permission. The attacker can mark orders as shipped, add fake notes under the victim's name, and send shipment emails to customers.

Detection Guidance

Check the installed version of the WC Vendors plugin in your WordPress admin panel. If it is below 2.7.2.1, the system is vulnerable. Review order logs for unauthorized shipment status changes or notes added by vendors who did not own the orders.

Impact Analysis

If you are a vendor using this plugin, an attacker could falsify order shipments, send misleading notifications to customers, and damage your reputation. Customers may receive incorrect shipment updates, leading to confusion or trust issues. The plugin's integrity and order management could be compromised.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to order data, potentially violating data integrity and accountability requirements under GDPR or HIPAA. False shipment records may lead to incorrect audit trails, affecting regulatory reporting and customer trust.

Mitigation Strategies

Update the WC Vendors plugin to version 2.7.2.1 or later immediately. If updating is not possible, disable the plugin temporarily until the update is applied. Monitor order activities for suspicious changes and restrict vendor permissions if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81427. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart