plugin

Smsa Shipping Official Vulnerabilities

4 known security issues reported for the Smsa Shipping Official WordPress plugin. Most recent disclosed Jan 6, 2026.

2 high

Running Smsa Shipping Official on your site? Check whether your installed version is affected.

Scan your site free

SMSA Shipping <= 2.3 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The SMSA Shipping (official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can ea...

CVSS:
8.1
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Jan 6, 2026

CVE-2024-49249 on NVD →

SMSA Shipping (official) [smsa-shipping-official] < 2.4

unknown

[en] Path Traversal vulnerability in SMSA Express SMSA Shipping allows Path Traversal.This issue affects SMSA Shipping: from n/a through 2.3.

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Jan 7, 2025

CVE-2024-49249 on NVD →

SMSA Shipping (official) [smsa-shipping-official] < 2.4

unknown

[en] The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arb...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Dec 21, 2024

CVE-2024-12066 on NVD →

SMSA Shipping(official) <= 2.3 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrar...

CVSS:
8.8
Affected:
up to 2.3
Fixed in:
2.4
Disclosed:
Dec 20, 2024

CVE-2024-12066 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database