ZeroHour

CVE-2026-84836

niche

Subscriber-Level IDOR in WC Ukraine Shipping WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-84836 is an Insecure Direct Object References (IDOR) flaw (CWE-639) in the WC Ukraine Shipping plugin for WordPress/WooCommerce, affecting all versions up to and including 1.22.3. An attacker who holds (or registers, if open registration is enabled) a subscriber-level account on an affected site can send requests referencing other users' or records' object identifiers and access data belonging to other accounts. Per the CVSS vector, the attacker gains high-confidence read access to sensitive information plus limited ability to modify data, with no user interaction required beyond the authenticated request. Only WordPress sites running WC Ukraine Shipping 1.22.3 or older are affected. There is currently no public proof-of-concept, no known in-the-wild exploitation, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (13th percentile).

What to do: Sites running WC Ukraine Shipping 1.22.3 or older should update to the first patched release after 1.22.3 (a specific fixed version number is not stated in the available data — verify the current version on the plugin's WordPress.org listing). Because exploitation requires subscriber-level authentication, the practical risk is highest on sites with open registration or many low-privilege accounts; audit subscriber accounts and restrict self-registration until patched. If no update is available, consider temporarily deactivating the plugin.

Affected
WC Ukraine Shipping (WordPress plugin) WC Ukraine Shipping<= 1.22.3
Estimated exposure
nichelikely low hundreds to low thousands of sites (estimate) — WC Ukraine Shipping is a niche regional shipping extension for WooCommerce serving Ukrainian merchants, a category of plugin that typically has a small active-install base, and no authoritative active-install count was available in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.