What is CVE-2026-16993?
CVE-2026-16993 affects the DHL Shipping Germany for WooCommerce WordPress plugin before version 4.0.1. The plugin protects its shipping-label storage directory only with an Apache .htaccess file, lacking server-independent access control, which exposes labels to unauthenticated access on servers like nginx that ignore .htaccess. Updating to version 4.0.1 or later is strongly advised.
Azərbaycanca: CVE-2026-16993, DHL Shipping Germany for WooCommerce WordPress plugin-in 4.0.1-dən əvvəlki versiyalarında aşkarlanmışdır. Plugin, shipping-label saxlama qovluğunu yalnız Apache .htaccess faylı ilə qoruyur; nginx kimi .htaccess-ə hörmət etməyən serverlərdə autentifikasiya olunmamış şəxslər bu etiketlərə daxil ola bilər. Plugin-i dərhal 4.0.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: WooCommerce, WordPress
FAQ1
Under what conditions can CVE-2026-16993 be exploited?
The vulnerability arises because the DHL Shipping Germany for WooCommerce plugin protects its shipping-label storage directory solely with an Apache .htaccess file. On servers like nginx that do not respect .htaccess, unauthenticated individuals can directly access these sensitive labels.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.