CVE-2026-93580
Received Received - Intake

InPost PL WordPress Plugin Shipment Status Forgery

Vulnerability report for CVE-2026-93580, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
inpost pl_wordpress_plugin to 1.9.8 (exc)
inpost wordpress_plugin to 1.9.8 (exc)
inpost woocommerce_plugin From 1.7.5 (inc) to 1.9.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The InPost PL WordPress plugin before version 1.9.8 has a flaw where it does not properly verify the authenticity of incoming shipment webhook requests. It relies on a non-secret identifier and an IP check that is not enforced, allowing attackers to forge shipment status if they know a target order's tracking number.

Detection Guidance

Check if the InPost PL WordPress plugin version is below 1.9.8. Use WordPress admin panel to view plugin versions or run commands like 'wp plugin list' in WP-CLI to list installed plugins and their versions.

Impact Analysis

An unauthenticated attacker could exploit this to forge shipment status and mark orders as completed prematurely. This could lead to financial losses, incorrect order fulfillment, or disruption of business operations if orders are processed before payment or verification.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized changes to order statuses, potentially violating data integrity and access control requirements in regulations like GDPR or HIPAA. Unauthorized order completion may also lead to breaches of transactional or financial data handling policies.

Mitigation Strategies

Update the InPost PL WordPress plugin to version 1.9.8 or later immediately. Disable webhook functionality if not required or restrict access to webhook endpoints via IP whitelisting until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93580. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart