CVE-2026-9235 Details
Description
The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hooks and act on an attacker-supplied post_id (WooCommerce order ID). This makes it possible for authenticated attackers, with Subscriber-level access and above, to create or delete DHL shipping labels associated with any WooCommerce order on the site.
A vulnerability exists in the DHL eCommerce (Benelux) for WooCommerce plugin for WordPress, specifically in versions through 2.2.3. The issue arises from a lack of proper capability checks and nonce verification in the 'create_label()' and 'delete_label()' functions. These functions, which are linked to the 'wp_ajax_dhlpwc_label_create' and 'wp_ajax_dhlpwc_label_delete' hooks, process an attacker-supplied 'post_id' (WooCommerce order ID). As a result, authenticated attackers with Subscriber-level access or higher can create or delete DHL shipping labels for any WooCommerce order on the site.
Users are advised to update the DHL eCommerce (Benelux) for WooCommerce plugin to version 2.2.4 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DHL eCommerce (Benelux) | <= 2.2.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion