CVE-2026-103378
Received Received - Intake

Geliver Akıllı Kargo Pazaryeri Plugin Unauthenticated Log File Access

Vulnerability report for CVE-2026-103378, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: WPScan

Description

The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Geliver Akıllı Kargo Pazaryeri 3.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Geliver Akıllı Kargo Pazaryeri WordPress plugin before version 3.1.1 stores a log file in a web-accessible directory. This log file contains the site's carrier integration key and sensitive customer information from processed orders. Attackers can access this log file without authentication to retrieve the API key and modify WooCommerce order statuses.

Detection Guidance

Check for the presence of the log file in the plugin's web-accessible directory, typically named similarly to the plugin. Use commands like 'curl http://your-site.com/wp-content/plugins/geliver-akilli-kargo-pazaryeri/log.txt' to attempt accessing the log file. If the log file is accessible and contains sensitive data like API keys or customer information, the vulnerability exists.

Impact Analysis

Attackers can use the exposed API key to modify WooCommerce order statuses, potentially altering order details. The log file also exposes customer information, leading to privacy breaches and potential misuse of sensitive data.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive customer data. GDPR requires protection of personal data, while HIPAA mandates safeguarding protected health information. Exposure of such data may result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update the Geliver Akıllı Kargo Pazaryeri plugin to version 3.1.1 or later to patch the vulnerability. If updating is not possible, restrict access to the plugin's directory by modifying server permissions or using .htaccess rules to block external access to the log file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103378. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart