CVE-2026-16993: CWE-200 Information Exposure in DHL Shipping Germany for WooCommerce
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.
AI Analysis
Technical Summary
The DHL Shipping Germany for WooCommerce plugin prior to version 4.0.1 fails to implement server-independent access controls on its shipping-label storage directory. It relies solely on an Apache .htaccess file for protection, which is ineffective on web servers like nginx that do not process .htaccess files. This allows unauthenticated users to access and download shipping labels containing sensitive customer information by requesting predictable filenames, leading to information disclosure classified under CWE-200.
Potential Impact
An unauthenticated attacker can access and download shipping labels containing customers' names and postal addresses. This results in exposure of personally identifiable information (PII), potentially violating privacy and data protection regulations. There is no indication of further exploitation or active attacks in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or update is available, administrators should implement server-level access controls independent of .htaccess files, such as configuring nginx or other web servers to restrict access to the shipping-label storage directory. Alternatively, consider restricting access to trusted users or disabling the plugin if feasible.
CVE-2026-16993: CWE-200 Information Exposure in DHL Shipping Germany for WooCommerce
Description
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.
CVSS v3.1
Score 3.7low
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The DHL Shipping Germany for WooCommerce plugin prior to version 4.0.1 fails to implement server-independent access controls on its shipping-label storage directory. It relies solely on an Apache .htaccess file for protection, which is ineffective on web servers like nginx that do not process .htaccess files. This allows unauthenticated users to access and download shipping labels containing sensitive customer information by requesting predictable filenames, leading to information disclosure classified under CWE-200.
Potential Impact
An unauthenticated attacker can access and download shipping labels containing customers' names and postal addresses. This results in exposure of personally identifiable information (PII), potentially violating privacy and data protection regulations. There is no indication of further exploitation or active attacks in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix or update is available, administrators should implement server-level access controls independent of .htaccess files, such as configuring nginx or other web servers to restrict access to the shipping-label storage directory. Alternatively, consider restricting access to trusted users or disabling the plugin if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-24T08:54:56.901Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a72d7b0bf8831d5395e835c
Added to database: 08/05/2026, 06:26:56 UTC
Last enriched: 08/05/2026, 07:01:13 UTC
Last updated: 08/06/2026, 00:41:11 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.