VYPR

Orders Tracking for WooCommerce

by WordPress

CVEs (3)

  • CVE-2024-4039MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before…

  • CVE-2021-25062MedJan 24, 2022
    risk 0.33cvss 6.1epss 0.01

    The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

  • CVE-2023-4216LowSep 4, 2023
    risk 0.18cvss 2.7epss 0.01

    The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content…