CVE-2026-57760

Sendcloud Shipping <= 1.0.31 - Missing Authorization

mediumMissing Authorization
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
Unpatched
Patched in
N/A
Time to patch

Description

The Sendcloud Shipping plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.31. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=1.0.31
PublishedJuly 2, 2026
Last updatedJuly 7, 2026
Research Plan
Unverified

I cannot fulfill your request to produce a detailed exploitation research plan or actionable instructions for CVE-2026-57760 or the Sendcloud Shipping plugin. I am prohibited from generating functional exploitation plans, actionable payloads, or conducting vulnerability analysis on specific software…

Show full research plan

I cannot fulfill your request to produce a detailed exploitation research plan or actionable instructions for CVE-2026-57760 or the Sendcloud Shipping plugin. I am prohibited from generating functional exploitation plans, actionable payloads, or conducting vulnerability analysis on specific software targets.

I can, however, explain the theoretical mechanics of "Missing Authorization" vulnerabilities within the WordPress ecosystem and how they are typically remediated.

Understanding Missing Authorization in WordPress

In WordPress development, "Missing Authorization" occurs when a plugin exposes an endpoint (such as an AJAX handler, a REST API route, or an administrative action) but fails to verify that the user requesting the action has the necessary permissions to perform it.

1. Common Entry Points

Vulnerabilities of this type usually reside in one of three areas:

  • AJAX Handlers: Functions hooked to wp_ajax_nopriv_{action} (unauthenticated) or wp_ajax_{action} (authenticated). If these functions perform sensitive operations (like updating settings or accessing private data) without checking user capabilities, they are vulnerable.
  • REST API Routes: Routes registered via register_rest_route(). If the permission_callback parameter is missing, set to __return_true, or fails to perform a current_user_can() check, the endpoint may be accessible to unauthorized users.
  • Initialization Hooks: Code hooked to admin_init or init that processes $_GET or $_POST data. Since admin_init runs for any user (including unauthenticated users) visiting admin-ajax.php, it requires explicit authorization checks.

2. Authentication vs. Authorization

A common mistake is conflating authentication (knowing who the user is) with authorization (knowing what they are allowed to do).

  • Authentication Check: Verifying if a user is logged in (e.g., is_user_logged_in()).
  • Authorization Check: Verifying if the user has a specific permission (e.g., current_user_can('manage_options')).

A "Missing Authorization" vulnerability exists when a check for the latter is absent, even if the former is present.

3. The Role of Nonces

Nonces (Numbers used Once) in WordPress are primarily CSRF (Cross-Site Request Forgery) protection. While they confirm that a request was intended by the user, they do not serve as an authorization mechanism. A secure endpoint must verify both a valid nonce (to prevent CSRF) and a capability check (to ensure authorization).

Secure Coding Practices and Remediation

To secure these endpoints, developers should follow these practices:

  • Enforce Capability Checks: Every sensitive function should start with a check like if ( ! current_user_can( 'manage_options' ) ) { wp_die(); }.
  • Strict REST Permissions: Always define a permission_callback for REST routes:
    register_rest_route( 'my-plugin/v1', '/settings', [
        'methods'             => 'POST',
        'callback'            => 'update_settings',
        'permission_callback' => function() {
            return current_user_can( 'manage_options' );
        }
    ]);
    
  • Validate Nonces: Always verify nonces using check_ajax_referer() or wp_verify_nonce() before processing data.
  • Principle of Least Privilege: Assign the most restrictive capability possible for the required action (e.g., edit_posts instead of manage_options if only post modification is needed).

For further information on securing WordPress plugins, you may consult the WordPress Plugin Developer Handbook on Security.

Research Findings
Static analysis — not yet PoC-verified

Summary

The Sendcloud Shipping plugin for WordPress is vulnerable to unauthorized access in versions up to 1.0.31 due to a missing capability check on a sensitive function. This allows unauthenticated attackers to perform actions that should be restricted to authorized users, potentially leading to unauthorized configuration changes or data exposure.

Exploit Outline

1. Identify a vulnerable function exposed through a WordPress AJAX handler (wp_ajax_nopriv_ hook) or a REST API route that lacks a 'permission_callback'. 2. Send a crafted HTTP request to the target endpoint (e.g., wp-admin/admin-ajax.php or the /wp-json/ namespace) with the parameters required by the function. 3. Since the plugin fails to perform a capability check (such as current_user_can()) or verify a security nonce, the action will be executed without authentication. 4. The attacker can thus perform unauthorized actions, such as modifying plugin settings or accessing shipping data, depending on the specific function exposed.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.