DPD Baltic Shipping <= 1.2.93 - Embedded Malicious Code (Password-Protected File Manager in uninstall-boolean.php)

Critical 9.8 CWE-506Fixed in 1.2.94
ID
WPSEC-2026-0639
Plugin
DPD Baltic Shipping (woo-shipping-dpd-baltic)
Affected
from 1.2.93 before 1.2.94
Remediation
Update to 1.2.94 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-506
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-08
Attack surface
DPD Baltic Shipping on WPSec AttackSurface
Fix released
Published

Description

Version 1.2.93 of the DPD Baltic Shipping plugin for WordPress, as originally distributed on WordPress.org between 2026-09-30 and 2026-10-07, included a file named uninstall-boolean.php that is not part of the plugin's functionality. The file is a complete web-based file manager that can be opened directly by its URL inside the plugin directory, is protected only by a single password whose hash is embedded in the file, and operates on the web server's document root. Anyone who knows that password can browse, read, upload, modify and delete files on the server, including wp-config.php, which allows complete takeover of the site. Version 1.2.94 removes the file from the package and deletes it from existing installations. Site owners who ran 1.2.93 should update, confirm that uninstall-boolean.php is no longer present in the plugin directory, and check the site for unexpected files or administrator accounts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0