PatchSiren

wpexpertshub CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wpexpertshub CVE published 2026-09-19

CVE-2026-9858

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4. This vulnerability allows authenticated attackers with Subscriber-level access and above to read arbitrary order item details and modify shipment status. The vulnerability is caused by the AJAX handlers in woocommerce-partial-shipment.php lacking capability checks and non [truncated]