← WordPress Vulnerabilities
WordPress security by component

Colissimo Officiel : Méthodes de livraison pour WooCommerce

Colissimo Officiel : Méthodes de livraison pour WooCommerce is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 6.5.

Plugin slug: colissimo-shipping-methods-for-woocommerce

CVE-2026-66692: Colissimo Officiel contains a Customer-level insecure direct object reference

Colissimo Officiel through 2.10.0 contains an IDOR reachable by an authenticated WooCommerce Customer. A customer-controlled object reference reaches an operation without an ownership check, but the CNA does not disclose the endpoint or action, identifier parameter, object type, or whether exploitation reads or changes the object.

PublishedAug 06, 2026
Known safe version3.0.0
Published vulnerabilities for colissimo-shipping-methods-for-woocommerce
Safe version
Aug 06, 2026 CVE-2026-66692
Colissimo Officiel contains a Customer-level insecure direct object reference
Colissimo Officiel through 2.10.0 contains an IDOR reachable by an authenticated WooCommerce Customer. A customer-controlled object reference reaches an operation without an ownership check, but the CNA does not disclose the endpoint or action, identifier parameter, object type, or whether exploitation reads or changes the object.
3.0.0
CVE4.3
NVDPending
Jul 09, 2026 CVE-2026-9240
Colissimo shipping methods for WooCommerce: A security weakness
Colissimo shipping methods for WooCommerce is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.0.
> 2.9.0
CVE4.3
NVDPending
Jun 29, 2026 CVE-2026-57341
Colissimo Officiel : Méthodes de livraison pour WooCommerce: A security weakness
Colissimo Officiel : Méthodes de livraison pour WooCommerce is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.9.0.
2.10.0
CVE6.5
NVDPending