---
id: CVE-2026-93580
title: >-
  The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity
  of incoming shipment webhook requests, relying only on a non-secret identifier
  and an IP check that is not enforced, allowing unauthenticated attackers who
  know…
summary: >-
  The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity
  of incoming shipment webhook requests, relying only on a non-secret identifier
  and an IP check that is not enforced, allowing unauthenticated attackers who
  know…
severity: none
cwe:
  - CWE-862
product: InPost PL
affected:
  - inpost_pl >= 1.7.5 < 1.9.8
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:10.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93580'
references:
  - url: 'https://wpscan.com/vulnerability/083dab74-cffe-4532-8fc3-939a015c83d4/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.558Z'
---

## Overview

The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
