[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdM1T_SveHnUI2IBQF-1ukQJm6WI83b67xXuGc18OH2M":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":25,"research_model_used":26,"research_started_at":27,"research_completed_at":28,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":29},"CVE-2026-57760","sendcloud-shipping-missing-authorization","Sendcloud Shipping \u003C= 1.0.31 - Missing Authorization","The Sendcloud Shipping plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.31. This makes it possible for unauthenticated attackers to perform an unauthorized action.","sendcloud-connected-shipping",null,"\u003C=1.0.31","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-07-02 00:00:00","2026-07-07 19:40:26",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F067b70a5-ad1a-446f-832f-cbf3088d2f59?source=api-prod",[],"researched",false,3,"I cannot fulfill your request to produce a detailed exploitation research plan or actionable instructions for CVE-2026-57760 or the Sendcloud Shipping plugin. I am prohibited from generating functional exploitation plans, actionable payloads, or conducting vulnerability analysis on specific software targets.\n\nI can, however, explain the theoretical mechanics of \"Missing Authorization\" vulnerabilities within the WordPress ecosystem and how they are typically remediated.\n\n### Understanding Missing Authorization in WordPress\n\nIn WordPress development, \"Missing Authorization\" occurs when a plugin exposes an endpoint (such as an AJAX handler, a REST API route, or an administrative action) but fails to verify that the user requesting the action has the necessary permissions to perform it.\n\n#### 1. Common Entry Points\nVulnerabilities of this type usually reside in one of three areas:\n\n*   **AJAX Handlers:** Functions hooked to `wp_ajax_nopriv_{action}` (unauthenticated) or `wp_ajax_{action}` (authenticated). If these functions perform sensitive operations (like updating settings or accessing private data) without checking user capabilities, they are vulnerable.\n*   **REST API Routes:** Routes registered via `register_rest_route()`. If the `permission_callback` parameter is missing, set to `__return_true`, or fails to perform a `current_user_can()` check, the endpoint may be accessible to unauthorized users.\n*   **Initialization Hooks:** Code hooked to `admin_init` or `init` that processes `$_GET` or `$_POST` data. Since `admin_init` runs for any user (including unauthenticated users) visiting `admin-ajax.php`, it requires explicit authorization checks.\n\n#### 2. Authentication vs. Authorization\nA common mistake is conflating authentication (knowing who the user is) with authorization (knowing what they are allowed to do).\n*   **Authentication Check:** Verifying if a user is logged in (e.g., `is_user_logged_in()`).\n*   **Authorization Check:** Verifying if the user has a specific permission (e.g., `current_user_can('manage_options')`).\n\nA \"Missing Authorization\" vulnerability exists when a check for the latter is absent, even if the former is present.\n\n#### 3. The Role of Nonces\nNonces (Numbers used Once) in WordPress are primarily CSRF (Cross-Site Request Forgery) protection. While they confirm that a request was intended by the user, they do not serve as an authorization mechanism. A secure endpoint must verify both a valid nonce (to prevent CSRF) and a capability check (to ensure authorization).\n\n### Secure Coding Practices and Remediation\n\nTo secure these endpoints, developers should follow these practices:\n\n*   **Enforce Capability Checks:** Every sensitive function should start with a check like `if ( ! current_user_can( 'manage_options' ) ) { wp_die(); }`.\n*   **Strict REST Permissions:** Always define a `permission_callback` for REST routes:\n    ```php\n    register_rest_route( 'my-plugin\u002Fv1', '\u002Fsettings', [\n        'methods'             => 'POST',\n        'callback'            => 'update_settings',\n        'permission_callback' => function() {\n            return current_user_can( 'manage_options' );\n        }\n    ]);\n    ```\n*   **Validate Nonces:** Always verify nonces using `check_ajax_referer()` or `wp_verify_nonce()` before processing data.\n*   **Principle of Least Privilege:** Assign the most restrictive capability possible for the required action (e.g., `edit_posts` instead of `manage_options` if only post modification is needed).\n\nFor further information on securing WordPress plugins, you may consult the [WordPress Plugin Developer Handbook on Security](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F).","The Sendcloud Shipping plugin for WordPress is vulnerable to unauthorized access in versions up to 1.0.31 due to a missing capability check on a sensitive function. This allows unauthenticated attackers to perform actions that should be restricted to authorized users, potentially leading to unauthorized configuration changes or data exposure.","1. Identify a vulnerable function exposed through a WordPress AJAX handler (wp_ajax_nopriv_ hook) or a REST API route that lacks a 'permission_callback'.\n2. Send a crafted HTTP request to the target endpoint (e.g., wp-admin\u002Fadmin-ajax.php or the \u002Fwp-json\u002F namespace) with the parameters required by the function.\n3. Since the plugin fails to perform a capability check (such as current_user_can()) or verify a security nonce, the action will be executed without authentication.\n4. The attacker can thus perform unauthorized actions, such as modifying plugin settings or accessing shipping data, depending on the specific function exposed.","gemini-3-flash-preview","2026-07-25 10:46:47","2026-07-25 10:47:37",{"type":30,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":31},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fsendcloud-connected-shipping\u002Ftags"]