Skip to content
WordPress.org
  • News
  • Showcase
  • Hosting
    • Themes
    • Plugins
    • Patterns
    • Blocks
    • Openverse ↗︎
    • Learn WordPress
    • Documentation
    • Forums
    • Developers
    • WordPress.tv ↗︎
    • Make WordPress
    • Education
    • Photo Directory
    • Five for the Future
    • Events
    • Job Board ↗︎
    • About WordPress
    • Enterprise
    • Gutenberg ↗︎
    • Swag Store ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Forums

  • Welcome to Support
  • Guidelines
  • Get involved
  • Log in
  • Welcome to Support
  • Guidelines
  • Get involved
  • Log in
Skip to content

Forums / Plugin: Shiprocket / Vulnerability – Authorization Bypass Through User-Controlled Key

Vulnerability – Authorization Bypass Through User-Controlled Key

  • thorsolutions

    (@thorsolutions)


    1 month, 2 weeks ago

    https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/shiprocket/shiprocket-208-authenticated-subscriber-insecure-direct-object-reference

    Considering how horrible Shiprocket support in general is, can we even expect a patch anytime soon?

You must be logged in to reply to this topic.

  • Shiprocket
  • Support Threads
  • Active Topics
  • Unresolved Topics
  • Reviews
  • 0 replies
  • 1 participant
  • Last reply from: thorsolutions
  • Last activity: 1 month, 2 weeks ago
  • Status: not resolved
  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Five for the Future
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry
The WordPress® trademark is the intellectual property of the WordPress Foundation.