AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-16993

LOW · CVSS 3.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The DHL Shipping Germany plugin for WooCommerce prior to version 4.0.1 is vulnerable due to inadequate access controls on its shipping-label storage directory, relying solely on an Apache .htaccess file. This misconfiguration allows unauthenticated users on servers like Nginx to access and download sensitive shipping labels, which include customer names and addresses. E-commerce operators using this plugin should prioritize patching to mitigate the risk of exposing customer data.

CVE
CVE-2026-16993
Severity
LOW
CVSS
3.7
EPSS
0.17%
WordPress Apache Nginx

Original NVD Description

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.