天下漏洞,尽知其名
MEDIUM

CVE-2026-87846 Shipping for Nova Poshta 缺失授权漏洞

原始情报

The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyone to delete the shipment records of arbitrary orders and to make the store issue the carrier’s waybill-deletion request for those orders using the store’s own stored API credentials.