Torod – The smart shipping and delivery portal for e-shops and retailers [torod] <= 1.9 (unfixed)
unknown
[en] The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the save_settings function. This makes it possible for unauthenticated att...
- Affected:
- up to 1.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 5, 2025
CVE-2025-12373 on NVD →
Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification
medium
The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the save_settings function. This makes it possible for unauthenticated attacker...
- CVSS:
- 4.3
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Dec 4, 2025
CVE-2025-12373 on NVD →
Torod – The smart shipping and delivery portal for e-shops and retailers [torod] <= 1.9 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod allows SQL Injection. This issue affects Torod: from n/a through 1.9.
- Affected:
- up to 1.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 16, 2025
CVE-2025-30936 on NVD →
Torod <= 1.9 - Unauthenticated SQL Injection
high
The Torod plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alread...
- CVSS:
- 7.5
- Affected:
- up to 1.9
- Fix:
- No patched version reported
- Disclosed:
- Jul 7, 2025
CVE-2025-30936 on NVD →
Torod – The smart shipping and delivery portal for e-shops and retailers [torod] < 1.8
unknown
[en] Missing Authorization vulnerability in Torod Holding LTD Torod allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Torod: from n/a through 1.7.
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Dec 31, 2024
CVE-2024-55995 on NVD →
Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.7 - Missing Authorization to Unauthenticated Plugin Settings Update
medium
The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to update the plugin's settings.
- CVSS:
- 6.5
- Affected:
- up to 1.7
- Fixed in:
- 1.8
- Disclosed:
- Dec 14, 2024
CVE-2024-55995 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database