plugin

Torod Vulnerabilities

6 known security issues reported for the Torod WordPress plugin. Most recent disclosed Dec 5, 2025.

1 high 2 medium

Running Torod on your site? Check whether your installed version is affected.

Scan your site free

Torod &#8211; The smart shipping and delivery portal for e-shops and retailers [torod] <= 1.9 (unfixed)

unknown

[en] The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the save_settings function. This makes it possible for unauthenticated att...

Affected:
up to 1.9
Fix:
No patched version reported
Disclosed:
Dec 5, 2025

CVE-2025-12373 on NVD →

Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification

medium

The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the save_settings function. This makes it possible for unauthenticated attacker...

CVSS:
4.3
Affected:
up to 1.9
Fixed in:
2.0
Disclosed:
Dec 4, 2025

CVE-2025-12373 on NVD →

Torod &#8211; The smart shipping and delivery portal for e-shops and retailers [torod] <= 1.9 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod allows SQL Injection. This issue affects Torod: from n/a through 1.9.

Affected:
up to 1.9
Fix:
No patched version reported
Disclosed:
Jul 16, 2025

CVE-2025-30936 on NVD →

Torod <= 1.9 - Unauthenticated SQL Injection

high

The Torod plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into alread...

CVSS:
7.5
Affected:
up to 1.9
Fix:
No patched version reported
Disclosed:
Jul 7, 2025

CVE-2025-30936 on NVD →

Torod &#8211; The smart shipping and delivery portal for e-shops and retailers [torod] < 1.8

unknown

[en] Missing Authorization vulnerability in Torod Holding LTD Torod allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Torod: from n/a through 1.7.

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Dec 31, 2024

CVE-2024-55995 on NVD →

Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.7 - Missing Authorization to Unauthenticated Plugin Settings Update

medium

The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to update the plugin's settings.

CVSS:
6.5
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
Dec 14, 2024

CVE-2024-55995 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database