PatchSiren

DHL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review DHL CVE published 2026-08-05

CVE-2026-16993

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file. On a web server that does not honor .htaccess, such as nginx, an unauthenticated visitor can download stored shipping labels by requesting predictable filenames.

Review DHL CVE published 2026-08-05

CVE-2026-16981

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 has a vulnerability allowing unauthenticated attackers to download stored shipping labels containing customer information. This vulnerability allows attackers to enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference. The vulnerability is [truncated]