CVE-2026-103685: Villatheme Ald – Dropshipping And Fulfillment For Aliexpress And Woocommerce
Medium severity, CVSS 4.3.
Missing Authorization vulnerability in VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 2.2.4.
Affected products
- Villatheme Ald – Dropshipping And Fulfillment For Aliexpress And Woocommerce: up to and including 2.2.4
Published 2026-10-10. Last modified 2026-10-10.