CVE-2026-103378

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam

    NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 7 Oct 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📂 Pre-auth arbitrary file read — the server returns its own deployment descriptor, then the config and credentials beside it, with no login (Atlassian CVE-2026-21589) 📦 Plugin writing a credential to a world-readable log — the shipping carrier's API key, and with it the power to change order statuses (Geliver CVE-2026-103378) 📦 REST routes registered with no permission check — unpublished store records read anonymously (WPCafe CVE-2026-86816) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #PathTraversal #CSO #REDTEAM

    0000037
    6 followersView on X

Explore more