CVE-2026-39583

Datalogics · Ecommerce Delivery

An unauthenticated privilege escalation vulnerability exists in the Datalogics Ecommerce Delivery WordPress plugin, allowing attackers to gain administrative access.

Executive summary

The Datalogics Ecommerce Delivery plugin is affected by a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrative control over the application.

Vulnerability

This vulnerability allows unauthenticated attackers to elevate their privileges to that of an administrator within the Datalogics Ecommerce Delivery plugin for WordPress, bypassing standard security controls.

Business impact

The exploit of this vulnerability grants full administrative access to the affected WordPress installation. Given the CVSS score of 9.8, this represents a critical risk that could lead to complete system compromise, unauthorized data exfiltration, and the deployment of malicious payloads, causing significant reputational and operational damage.

Remediation

Immediate Action: Update the Datalogics Ecommerce Delivery plugin to version 2.6.63 or later immediately.

Proactive Monitoring: Review WordPress user access logs for suspicious account creation or modifications to administrative user roles.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block unauthorized attempts to access administrative functions or modify user privileges.

Exploitation status

Public Exploit Available: False

Analyst recommendation

This vulnerability presents a severe risk to the integrity of the affected environment. Administrators must prioritize updating the plugin to version 2.6.63 or later to mitigate the risk of administrative takeover.