What is CVE-2026-16981?
CVE-2026-16981 affects the DHL Shipping Germany for WooCommerce plugin. Versions before 4.0.1 have a vulnerable shipping-label download endpoint that lacks any authorization check (no capability, nonce, login, or ownership verification), allowing an unauthenticated attacker to enumerate sequential IDs and download all stored shipping labels. Sites using the plugin should immediately update to version 4.0.1 or later.
Azərbaycanca: CVE-2026-16981, WooCommerce üçün DHL Shipping Germany plaginində aşkarlanıb. 4.0.1 versiyasından əvvəlki versiyalarda "shipping-label download" endpointində heç bir avtorizasiya yoxlaması aparılmır, bu da autentifikasiya olunmamış hücumçuya ardıcıl ID-ləri sınaqdan keçirərək mağazada saxlanılan bütün çatdırılma etiketlərini yükləməyə imkan verir. Plagindən istifadə edən saytlar dərhal versiyanı ən azı 4.0.1-ə yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
How does CVE-2026-16981 affect the DHL Shipping Germany plugin?
CVE-2026-16981 affects the DHL Shipping Germany for WooCommerce plugin in versions before 4.0.1, where the shipping-label download endpoint lacks any authorization check, allowing an unauthenticated attacker to enumerate sequential IDs and download all stored shipping labels.
What should I do to protect against CVE-2026-16981?
Sites using the DHL Shipping Germany for WooCommerce plugin should immediately update to version 4.0.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.