[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ff1qmc2DKFcXfwwtgqYk7vv8TojIE4lBkYFXCDDcGzCI":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":22,"research_verified":23,"research_rounds_completed":24,"research_plan":25,"research_summary":26,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":27,"research_started_at":28,"research_completed_at":29,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":23,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":23,"source_links":30},"CVE-2026-57352","ald-dropshipping-and-fulfillment-for-aliexpress-and-woocommerce-missing-authorization","ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce \u003C= 2.2.0 - Missing Authorization","The ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.","woo-alidropship",null,"\u003C=2.2.0","2.2.1","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-07-01 00:00:00","2026-07-09 13:42:23",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Febed1706-0790-447a-a535-4a46a8257f79?source=api-prod",9,[],"researched",false,3,"I cannot fulfill your request to produce a detailed exploitation research plan or actionable payloads for CVE-2026-57352 or the ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin. My instructions prohibit the generation of functional exploitation guides or attack inputs for specific, concrete targets.\n\nFor information on how to secure WordPress plugins against unauthorized access and how to properly implement authorization controls, I recommend consulting the following official resources:\n\n*   **WordPress Plugin Handbook on Security**: Provides comprehensive guidance on checking user capabilities and using nonces correctly. Search for \"WordPress Plugin Handbook Security\" online.\n*   **WordPress Developer Reference for `current_user_can()`**: Details how to implement proper authorization checks within plugin functions.\n*   **OWASP WordPress Security Implementation Guide**: Offers best practices for securing WordPress installations and developing safe plugins.\n*   **Common Weakness Enumeration (CWE) for Missing Authorization (CWE-862)**: Explains the underlying principles of this vulnerability type and general mitigation strategies.\n\nYou can find detailed security practices by searching for \"WordPress secure AJAX handlers\" or \"WordPress capability check best practices\" on major search engines.","The ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.0. This flaw allows unauthenticated attackers to perform unauthorized actions on the affected site.","gemini-3-flash-preview","2026-07-25 12:12:11","2026-07-25 12:12:49",{"type":31,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":32},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwoo-alidropship\u002Ftags"]