๐Ÿ” CVE Alert

CVE-2026-93580

UNKNOWN 0.0

InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.

Vendor unknown
Product inpost pl
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown inpost pl

Be the first to know when new unknown vulnerabilities affecting unknown inpost pl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / InPost PL
1.7.5 < 1.9.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/083dab74-cffe-4532-8fc3-939a015c83d4/

Credits

ryan fabella WPScan