← WordPress Vulnerabilities
WordPress security by component

DHL Shipping Germany for WooCommerce

DHL Shipping Germany for WooCommerce adds DHL shipping methods and services for WooCommerce orders in Germany.

DHL Shipping Germany for WooCommerce (dhl-shipping-germany-for-woocommerce) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 5.3.

Plugin slug: dhl-shipping-germany-for-woocommerce

CVE-2026-16993: DHL Shipping label files can be downloaded directly on nginx

DHL Shipping Germany for WooCommerce before 4.0.1 relies on an Apache .htaccess file to deny access to its shipping-label storage directory. Servers that do not honor .htaccess, including nginx unless separately configured, can therefore serve labels directly to unauthenticated visitors. Predictable filenames allow label discovery and expose customer names and postal addresses. This unscored record received deeper review because it provides an unauthenticated sensitive-file disclosure primitive; the CNA does not disclose the directory path or exact filename pattern.

PublishedAug 05, 2026
Known safe version4.0.1
Published vulnerabilities for dhl-shipping-germany-for-woocommerce
Safe version
Aug 05, 2026 CVE-2026-16993
DHL Shipping label files can be downloaded directly on nginx
DHL Shipping Germany for WooCommerce before 4.0.1 relies on an Apache .htaccess file to deny access to its shipping-label storage directory. Servers that do not honor .htaccess, including nginx unless separately configured, can therefore serve labels directly to unauthenticated visitors. Predictable filenames allow label discovery and expose customer names and postal addresses. This unscored record received deeper review because it provides an unauthenticated sensitive-file disclosure primitive; the CNA does not disclose the directory path or exact filename pattern.
4.0.1
CVE3.7
NVDPending
Aug 05, 2026 CVE-2026-16981
DHL Shipping label endpoint permits unauthenticated order disclosure
DHL Shipping Germany for WooCommerce before 4.0.1 exposes a shipping-label download endpoint without a login, capability, nonce or order-ownership check. An unauthenticated attacker can enumerate sequential record IDs and download stored labels containing customer names, full postal addresses and order references. This unscored record received deeper review because it provides an unauthenticated sensitive-data disclosure primitive; the CNA does not disclose the endpoint path or parameter name.
4.0.1
CVE5.3
NVDPending