CVE-2026-93580: Unknown Inpost Pl

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.

Affected products

  • Unknown Inpost Pl: from 1.7.5, before 1.9.8 (fixed in 1.9.8)

Published 2026-09-30. Last modified 2026-09-30.