CyberRota Analysis
AI-GeneratedThe DHL Shipping Germany plugin for WooCommerce prior to version 4.0.1 is vulnerable due to inadequate access controls on its shipping-label storage directory, relying solely on an Apache .htaccess file. This misconfiguration allows unauthenticated users on servers like Nginx to access and download sensitive shipping labels, which include customer names and addresses. E-commerce operators using this plugin should prioritize patching to mitigate the risk of exposing customer data.
Original NVD Description
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.