Access violation vulnerability in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce 1.0.21

The ALD Dropping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data in versions up to 1.0.21. This means that people who do not have permission can retrieve information about orders or make changes to them. The issue is caused by the lack of protection on certain functions like ‘update_ali_order_id’, ‘ob_get_clean’, and ‘get_ali_order_detail’.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.