synced 11 MIN AGO
01 Record

CVE-2026-9858

Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions

MediumPUBLISHEDCNA: Wordfence
CNA base score4.3 CVSS v3.xCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

02 Description

Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions

03 Exploitation and scoring

Exploitation
Assessed, none found. CISA's assessment recorded neither public exploit code nor evidence of exploitation when it was made.
SSVC decision
  • ExploitationnoneCISA recorded no public exploit code and no evidence of exploitation.
  • AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
  • Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.
EPSS probability
0.35% probability of exploitation activity in the next 30 days.
EPSS percentile
Ranks above 26.3% of scored records. A rank, not a probability.
NVD base score
4.3 (CVSS v3.x), scored by the NVD independently of the CNA.
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
NVD analysis status
Deferred. NVD last modified this record on 2026-09-21.
Red Hat severity
No Red Hat rating. Red Hat rates the CVEs that affect its products.

Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.

04 Metadata

Published
2026-09-19 08:27Z8 DAYS AGO
Last updated
2026-09-20 00:35Z8 DAYS AGO
Reserved
2026-05-28
Assigning CNA
Wordfence
Record state
PUBLISHED
Severity
Medium (CVSS 4.3)
CNA CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses
Data version
5.2
Document digest
b67ce322e409ad646bffcd1153f66d48d103e3b6fdc709a0be5cad388f07cc99

05 Affected products

VendorProductVersionsPlatforms
wpexpertshubPartial Shipment for WooCommerce0 to 3.4—

06 References