The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.
Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)
Problem type
Affected products
datalogics
<= 2.6.65 - AFFECTED
References
https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed27b8-dbdc-4927-8019-52a622bfbff6?source=cve
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L679
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L691
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L809
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L198
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L244
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L5
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L76
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L646
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L679
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L691
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L809
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L198
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L244
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L5
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L76
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L646
https://plugins.trac.wordpress.org/changeset?reponame=&old=3552733%40datalogics&new=3552733%40datalogics
GitHub Security Advisories
GHSA-2m92-vwcx-jmjg
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to...
https://github.com/advisories/GHSA-2m92-vwcx-jmjgThe Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers.
https://nvd.nist.gov/vuln/detail/CVE-2026-9613
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L198
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L244
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L5
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L646
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L679
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L691
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L76
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L809
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L198
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L244
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L5
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L646
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L679
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L691
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L76
https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L809
https://plugins.trac.wordpress.org/changeset?reponame=&old=3552733%40datalogics&new=3552733%40datalogics
https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed27b8-dbdc-4927-8019-52a622bfbff6?source=cve
https://github.com/advisories/GHSA-2m92-vwcx-jmjg
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-9613Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-9613",
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"dateUpdated": "2026-09-19T08:27:23.913Z",
"dateReserved": "2026-05-26T16:29:51.747Z",
"datePublished": "2026-09-19T08:27:23.913Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence",
"dateUpdated": "2026-09-19T08:27:23.913Z"
},
"title": "Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)",
"descriptions": [
{
"lang": "en",
"value": "The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create and cancel real shipping orders through the external logistics API using the store's stored authentication token, modify arbitrary WooCommerce order post meta on any order, overwrite the plugin's stored API token, and trigger shipping notification emails to customers."
}
],
"affected": [
{
"vendor": "datalogics",
"product": "Datalogics Ecommerce Delivery – Datalogics",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "2.6.65"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-862 Missing Authorization",
"cweId": "CWE-862",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ed27b8-dbdc-4927-8019-52a622bfbff6?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L679"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L691"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L809"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L198"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L244"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L5"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L76"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.65/actions.php#L646"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L679"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L691"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L809"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L198"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L244"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L5"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L76"
},
{
"url": "https://plugins.trac.wordpress.org/browser/datalogics/tags/2.6.63/actions.php#L646"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3552733%40datalogics&new=3552733%40datalogics"
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
}
}
],
"timeline": [
{
"time": "2026-09-18T19:54:22.000Z",
"lang": "en",
"value": "Disclosed"
}
],
"credits": [
{
"lang": "en",
"value": "Benedictus Jovan (aillesiM)",
"type": "finder"
}
]
}
}
}