Dpdgroup develops a focused WooCommerce shipping plugin, a narrowly scoped extension serving e-commerce integration needs. The vulnerability exposure centers on web-application access-control and request-handling weaknesses, particularly cross-site request forgery and missing authorization checks, which are characteristic of plugin-based extensions interfacing with cart and order systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dpdgroup over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3999HIGH The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to dele | Dec 12, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-4000MEDIUM The WooCommerce Shipping WordPress plugin through 1.2.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Dec 12, 2022 | 4.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dpdgroup.
Media articles that mention a CVE ID that affects a product developed by Dpdgroup — matched by CVE ID, not by vendor name.