The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file. On a web server that does not honor .htaccess, such as nginx, an unauthenticated visitor can download stored shipping labels by requesting predictable filenames.
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 has a vulnerability allowing unauthenticated attackers to download stored shipping labels containing customer information. This vulnerability allows attackers to enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference. The vulnerability is [truncated]