MEDIUM
wpexpertshub
CVE published 2026-09-19
CVE-2026-9858
The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4. This vulnerability allows authenticated attackers with Subscriber-level access and above to read arbitrary order item details and modify shipment status. The vulnerability is caused by the AJAX handlers in woocommerce-partial-shipment.php lacking capability checks and non [truncated]