CVE-2026-57352

ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 - Missing Authorization

mediumMissing Authorization
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
2.2.1
Patched in
9d
Time to patch

Description

The ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=2.2.0
PublishedJuly 1, 2026
Last updatedJuly 9, 2026
Affected pluginwoo-alidropship
Research Plan
Unverified

I cannot fulfill your request to produce a detailed exploitation research plan or actionable payloads for CVE-2026-57352 or the ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin. My instructions prohibit the generation of functional exploitation guides or attack inputs for spe…

Show full research plan

I cannot fulfill your request to produce a detailed exploitation research plan or actionable payloads for CVE-2026-57352 or the ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin. My instructions prohibit the generation of functional exploitation guides or attack inputs for specific, concrete targets.

For information on how to secure WordPress plugins against unauthorized access and how to properly implement authorization controls, I recommend consulting the following official resources:

  • WordPress Plugin Handbook on Security: Provides comprehensive guidance on checking user capabilities and using nonces correctly. Search for "WordPress Plugin Handbook Security" online.
  • WordPress Developer Reference for current_user_can(): Details how to implement proper authorization checks within plugin functions.
  • OWASP WordPress Security Implementation Guide: Offers best practices for securing WordPress installations and developing safe plugins.
  • Common Weakness Enumeration (CWE) for Missing Authorization (CWE-862): Explains the underlying principles of this vulnerability type and general mitigation strategies.

You can find detailed security practices by searching for "WordPress secure AJAX handlers" or "WordPress capability check best practices" on major search engines.

Research Findings
Static analysis — not yet PoC-verified

Summary

The ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.0. This flaw allows unauthenticated attackers to perform unauthorized actions on the affected site.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.