CVE-2026-93580
InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.
| Vendor | unknown |
| Product | inpost pl |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown inpost pl
Be the first to know when new unknown vulnerabilities affecting unknown inpost pl are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / InPost PL
1.7.5 < 1.9.8
References
Credits
ryan fabella WPScan