CVE-2026-93580 Overview
CVE-2026-93580 affects the InPost PL WordPress plugin in versions prior to 1.9.8. The plugin fails to verify the authenticity of incoming shipment webhook requests. It relies on a non-secret identifier and an IP check that is not enforced. Unauthenticated attackers who know a target order's parcel tracking number can forge shipment status updates. This lets them prematurely mark orders as completed, disrupting order fulfillment workflows for WooCommerce merchants using InPost shipping integrations.
Critical Impact
Unauthenticated attackers can forge shipment webhook requests to mark WooCommerce orders as completed, enabling potential fraud against merchants using the InPost PL plugin.
Affected Products
- InPost PL WordPress plugin versions prior to 1.9.8
- WordPress sites running WooCommerce with InPost shipping integration
- Merchants relying on the plugin's shipment webhook endpoint for order state transitions
Discovery Timeline
- 2026-09-30 - CVE-2026-93580 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-93580
Vulnerability Analysis
The InPost PL plugin exposes a webhook endpoint intended to receive shipment status updates from the InPost carrier system. The endpoint does not implement cryptographic verification of inbound requests. Instead, it authenticates callers using a parcel tracking number, which functions as a non-secret identifier. The plugin's documented IP allowlist for legitimate InPost infrastructure is not actually enforced in code.
Because the tracking number is not a secret, any party that observes or guesses it can impersonate the carrier. Attackers can then submit crafted webhook payloads that transition WooCommerce orders into the completed state. Premature order completion can trigger downstream automation such as digital goods delivery, license issuance, or shipment of physical items before payment conditions are fully validated.
Root Cause
The root cause is missing authentication on a state-changing endpoint, categorized under Broken Access Control and Improper Authentication. The plugin conflates identification with authentication by treating a public tracking number as proof of origin. The absence of an enforced source IP check removes the only remaining network-layer safeguard.
Attack Vector
Exploitation requires network access to the target WordPress site and knowledge of a valid parcel tracking number. Tracking numbers can be obtained through order confirmation emails, customer accounts, predictable identifier patterns, or interception. The attacker sends a forged HTTP POST request to the plugin's webhook route with a payload that sets the shipment status to delivered or completed. The plugin accepts the request and updates the corresponding WooCommerce order status. No user interaction, credentials, or elevated privileges are required. See the WPScan Vulnerability Advisory for additional technical detail.
Detection Methods for CVE-2026-93580
Indicators of Compromise
- WooCommerce orders transitioning to completed status without a corresponding legitimate carrier callback in shipment logs
- Inbound HTTP requests to the InPost webhook endpoint from source IPs outside known InPost carrier ranges
- Unusual clustering of order status changes to completed within short time windows
- Webhook requests referencing valid tracking numbers but lacking expected carrier request headers or user agents
Detection Strategies
- Review web server access logs for POST requests targeting the InPost shipment webhook route and correlate source IPs against the carrier's published address ranges
- Compare WooCommerce order status transitions against carrier shipment event history to identify status changes without matching upstream events
- Alert on order state changes to completed that bypass expected intermediate states such as processing or shipped
Monitoring Recommendations
- Enable WordPress and WooCommerce audit logging to capture the origin of every order status change
- Forward web server and plugin logs to a centralized log platform for retention and correlation
- Establish baseline traffic patterns for the InPost webhook endpoint and alert on volume or source anomalies
How to Mitigate CVE-2026-93580
Immediate Actions Required
- Update the InPost PL WordPress plugin to version 1.9.8 or later on all affected sites
- Audit recent WooCommerce order status changes for unauthorized transitions to completed and reverse any fraudulent completions
- Review fulfillment automation triggered by completed orders during the exposure window and reconcile against actual payments and shipments
Patch Information
Upgrade to InPost PL plugin version 1.9.8 or later, which addresses the missing webhook authentication. Consult the WPScan Vulnerability Advisory for vendor-confirmed remediation details.
Workarounds
- Restrict access to the InPost webhook endpoint at the web server or WAF layer to InPost carrier IP ranges only
- Temporarily disable the InPost PL plugin if patching is not immediately possible and fulfillment workflows can tolerate manual status updates
- Add server-level rate limiting on the webhook endpoint to reduce brute-force enumeration of tracking numbers
# Example nginx configuration restricting the InPost webhook endpoint by source IP
location ~* /wp-json/inpost/.*/webhook {
allow 192.0.2.0/24; # Replace with published InPost carrier IP ranges
deny all;
proxy_pass http://wordpress_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
