WordPress security by component
Colissimo Officiel : Méthodes de livraison pour WooCommerce
Plugin description
Colissimo Officiel : Méthodes de livraison pour WooCommerce is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
colissimo-shipping-methods-for-woocommerceLatest vulnerability
CVE-2026-66692: Colissimo Officiel contains a Customer-level insecure direct object reference
Colissimo Officiel through 2.10.0 contains an IDOR reachable by an authenticated WooCommerce Customer. A customer-controlled object reference reaches an operation without an ownership check, but the CNA does not disclose the endpoint or action, identifier parameter, object type, or whether exploitation reads or changes the object.
| Safe version |
|
||
|---|---|---|---|
| Aug 06, 2026 |
CVE-2026-66692
Colissimo Officiel contains a Customer-level insecure direct object reference
Colissimo Officiel through 2.10.0 contains an IDOR reachable by an authenticated WooCommerce Customer. A customer-controlled object reference reaches an operation without an ownership check, but the CNA does not disclose the endpoint or action, identifier parameter, object type, or whether exploitation reads or changes the object.
|
3.0.0 |
CVE4.3
NVDPending
|
| Jul 09, 2026 |
CVE-2026-9240
Colissimo shipping methods for WooCommerce: A security weakness
Colissimo shipping methods for WooCommerce is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.0.
|
> 2.9.0 |
CVE4.3
NVDPending
|
| Jun 29, 2026 |
CVE-2026-57341
Colissimo Officiel : Méthodes de livraison pour WooCommerce: A security weakness
Colissimo Officiel : Méthodes de livraison pour WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.9.0.
|
2.10.0 |
CVE6.5
NVDPending
|