{
 "id": "WPSEC-2026-0639",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0639/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0639/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0639/index.md",
 "title": "DPD Baltic Shipping <= 1.2.93 - Embedded Malicious Code (Password-Protected File Manager in uninstall-boolean.php)",
 "description": "Version 1.2.93 of the DPD Baltic Shipping plugin for WordPress, as originally distributed on WordPress.org between 2026-09-30 and 2026-10-07, included a file named uninstall-boolean.php that is not part of the plugin's functionality. The file is a complete web-based file manager that can be opened directly by its URL inside the plugin directory, is protected only by a single password whose hash is embedded in the file, and operates on the web server's document root. Anyone who knows that password can browse, read, upload, modify and delete files on the server, including wp-config.php, which allows complete takeover of the site. Version 1.2.94 removes the file from the package and deletes it from existing installations. Site owners who ran 1.2.93 should update, confirm that uninstall-boolean.php is no longer present in the plugin directory, and check the site for unexpected files or administrator accounts.",
 "plugin": {
  "slug": "woo-shipping-dpd-baltic",
  "name": "DPD Baltic Shipping",
  "full_name": "DPD Baltic Shipping",
  "wordpress_org": "https://wordpress.org/plugins/woo-shipping-dpd-baltic/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woo-shipping-dpd-baltic/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woo-shipping-dpd-baltic"
 },
 "type": "BACKDOOR",
 "cwe": [
  "CWE-506"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 9.8,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "severity": "Critical"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.2.93",
    "from_inclusive": true,
    "to": "1.2.94",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.2.93 before 1.2.94"
  ]
 },
 "introduced_in": "1.2.93",
 "fixed_in": "1.2.94",
 "remediation": "Update to 1.2.94 or later.",
 "fix_released": "2026-10-07T10:05:59+00:00",
 "published": "2026-10-08T10:46:37+00:00",
 "updated": "2026-10-07T12:20:10.340874+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0639/",
  "https://plugins.svn.wordpress.org/woo-shipping-dpd-baltic/tags/1.2.94/",
  "https://wordpress.org/plugins/woo-shipping-dpd-baltic/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woo-shipping-dpd-baltic",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-08"
 }
}