# DPD Baltic Shipping <= 1.2.93 - Embedded Malicious Code (Password-Protected File Manager in uninstall-boolean.php)

- **ID:** WPSEC-2026-0639
- **Plugin:** DPD Baltic Shipping (`woo-shipping-dpd-baltic`), https://wordpress.org/plugins/woo-shipping-dpd-baltic/
- **Affected versions:** from 1.2.93 before 1.2.94
- **Fixed in:** 1.2.94 (Update to 1.2.94 or later.)
- **Severity:** Critical 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-506
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woo-shipping-dpd-baltic
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0639/

## Description

Version 1.2.93 of the DPD Baltic Shipping plugin for WordPress, as originally distributed on WordPress.org between 2026-09-30 and 2026-10-07, included a file named uninstall-boolean.php that is not part of the plugin's functionality. The file is a complete web-based file manager that can be opened directly by its URL inside the plugin directory, is protected only by a single password whose hash is embedded in the file, and operates on the web server's document root. Anyone who knows that password can browse, read, upload, modify and delete files on the server, including wp-config.php, which allows complete takeover of the site. Version 1.2.94 removes the file from the package and deletes it from existing installations. Site owners who ran 1.2.93 should update, confirm that uninstall-boolean.php is no longer present in the plugin directory, and check the site for unexpected files or administrator accounts.

## References

- https://wpsec.com/vuln/WPSEC-2026-0639/
- https://plugins.svn.wordpress.org/woo-shipping-dpd-baltic/tags/1.2.94/
- https://wordpress.org/plugins/woo-shipping-dpd-baltic/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0639/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
