CyberRota Analysis
AI-GeneratedThe DHL Shipping Germany for WooCommerce plugin prior to version 4.0.1 is vulnerable due to a lack of authorization checks on its shipping-label download endpoint, allowing unauthenticated attackers to enumerate IDs and access sensitive customer information, including names and addresses. This poses a significant risk of data exposure and privacy breaches. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference.