CVE-2026-65501: Vendidero Shiptastic For Woocommerce

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

Affected products

  • Vendidero Shiptastic For Woocommerce: up to and including 5.1.0

Published 2026-07-23. Last modified 2026-07-23.