目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-16993— DHL for WooCommerce < 4.0.1 未认证发货标签泄露漏洞

AI Predicted 7.5 Difficulty: Trivial EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1005 · Data from Local System

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
UnknownDHL Shipping Germany for WooCommerce< 4.0.1affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-16993の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory
ソース: CVE Program / CVE List V5
脆弱性説明
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
UnknownDHL Shipping Germany for WooCommerce 0 ~ 4.0.1 -

II. CVE-2026-16993の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-16993のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-16993 新闻报道 (1)

Same Patch Batch · Unknown · 2026-08-05 · 24 CVEs total

CVE-2026-16981DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
CVE-2026-16573Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
CVE-2026-16602Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure
CVE-2026-16583Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
CVE-2026-16561Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
CVE-2026-16603Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure
CVE-2026-16736User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registrati
CVE-2026-16613GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
CVE-2026-16604Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Co
CVE-2026-16746MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commission
CVE-2026-16605MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing
CVE-2026-16940Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path T
CVE-2026-16055Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_log
CVE-2026-16968GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
CVE-2026-16942WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
CVE-2025-15677GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
CVE-2026-14553Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
CVE-2026-15210Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeov
CVE-2026-15230YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclo
CVE-2026-15372WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider

Showing 20 of 24 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-16993へのコメント

まだコメントはありません


コメントを残す