AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66692

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Colissimo Officiel plugin for WooCommerce versions up to 2.10.0 is vulnerable to Insecure Direct Object References (IDOR), allowing unauthorized access to sensitive customer data. This could lead to data exposure or manipulation, impacting the privacy and security of user information. E-commerce businesses utilizing this plugin should prioritize remediation to safeguard customer data and maintain compliance with data protection regulations.

CVE
CVE-2026-66692
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.