plugin

Woo Advanced Shipment Tracking Vulnerabilities

4 known security issues reported for the Woo Advanced Shipment Tracking WordPress plugin. Most recent disclosed Jul 28, 2026.

1 critical 1 high 2 medium

Running Woo Advanced Shipment Tracking on your site? Check whether your installed version is affected.

Scan your site free

Advanced Shipment Tracking for WooCommerce <= 3.9 - Authenticated (Shop Manager+) SQL Injection via 'tracking_provider' Parameter

high

The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the `tracking_provider` parameter of the `POST /wp-json/wc-ast/v3/orders/<order_id>/shipment-trackings` REST endpoint in all versions up to, and including, 3.9. This is due to insufficient escaping on the user-supplie...

CVSS:
7.2
Affected:
up to 3.9
Fixed in:
3.9.1
Disclosed:
Jul 28, 2026

Advanced Shipment Tracking for WooCommerce <= 4.0 - Authenticated (Shop manager+) SQL Injection

medium

The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop...

CVSS:
4.9
Affected:
up to 4.0
Fixed in:
4.0.1
Disclosed:
Jul 2, 2026

CVE-2026-57773 on NVD →

Advanced Shipment Tracking for WooCommerce <= 3.5.2 - Cross-Site Request Forgery via paginate_shipping_provider_list and filter_shipping_provider_list

medium

The Advanced Shipment Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.2. This is due to missing or incorrect nonce validation on the paginate_shipping_provider_list and filter_shipping_provider_list functions. This makes it possible for unauthenticated att...

CVSS:
4.3
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Mar 28, 2023

CVE-2022-41635 on NVD →

Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change

critical

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 w...

CVSS:
9.9
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
Jul 26, 2021

CVE-2021-4347 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database