{"id":"CVE-2026-16993","published":"2026-08-05T07:16:37.097","lastModified":"2026-08-05T15:16:38.310","description":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames.","cvssScore":3.7,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/efcf57b5-f35e-4943-8a49-350aa8bf1b8a/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}