CVE-2026-9613 Details
Description
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.
A vulnerability exists in the Datalogics Ecommerce Delivery plugin for WordPress, specifically in versions up to and including 2.6.65. The issue stems from the plugin's failure to properly verify user authorization for certain actions. This flaw enables authenticated attackers with subscriber-level access or higher to bypass authorization and make unauthorized changes. Exploitation of this vulnerability allows for the creation and cancellation of real shipping orders through the external logistics API, using the store's authentication token. Additionally, attackers can modify any WooCommerce order's post meta, overwrite the plugin's API token, and send shipping notification emails to customers.
Users are advised to update the Datalogics Ecommerce Delivery plugin to version 2.6.66 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 19, 2026CISA-ADP
Assessed Sep 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Datalogics Ecommerce Delivery | <= 2.6.65 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 19, 2026 | CVE Modified | CISA-ADP |
| Sep 19, 2026 | New CVE Received | [email protected] |
Volerion