Advanced Shipment Tracking for WooCommerce <= 3.9 - Authenticated (Shop Manager+) SQL Injection via 'tracking_provider' Parameter
high
The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the `tracking_provider` parameter of the `POST /wp-json/wc-ast/v3/orders/<order_id>/shipment-trackings` REST endpoint in all versions up to, and including, 3.9. This is due to insufficient escaping on the user-supplie...
- CVSS:
- 7.2
- Affected:
- up to 3.9
- Fixed in:
- 3.9.1
- Disclosed:
- Jul 28, 2026
Advanced Shipment Tracking for WooCommerce <= 4.0 - Authenticated (Shop manager+) SQL Injection
medium
The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop...
- CVSS:
- 4.9
- Affected:
- up to 4.0
- Fixed in:
- 4.0.1
- Disclosed:
- Jul 2, 2026
CVE-2026-57773 on NVD →
Advanced Shipment Tracking for WooCommerce <= 3.5.2 - Cross-Site Request Forgery via paginate_shipping_provider_list and filter_shipping_provider_list
medium
The Advanced Shipment Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.2. This is due to missing or incorrect nonce validation on the paginate_shipping_provider_list and filter_shipping_provider_list functions. This makes it possible for unauthenticated att...
- CVSS:
- 4.3
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Mar 28, 2023
CVE-2022-41635 on NVD →
Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change
critical
The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 w...
- CVSS:
- 9.9
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.7
- Disclosed:
- Jul 26, 2021
CVE-2021-4347 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database