cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwoo-advanced-shipment-tracking woo-advanced-shipment-tracking

Direction: ascending
Jun 06, 2024

Advanced Shipment Tracking for WooCommerce # 5c90d0bbe8b27c274e81eac21e249c973385c7c1

Date
Jul 26, 2021
Research Description
Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] < 3.2.7 WordPress Advanced Shipment Tracking for WooCommerce plugin <= 3.2.6 - Authenticated WordPress Options Change vulnerability Authenticated WordPress Options Change vulnerability discovered by Jerome Bruandet in WordPress Advanced Shipment Tracking for WooCommerce plugin (versions <= 3.2.6).
Affected versions
max 3.2.7.
Status
vulnerable

Advanced Shipment Tracking for WooCommerce # CVE-2022-41635

CVE, Research URL

CVE-2022-41635

Date
May 25, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions.
Affected versions
max 3.5.3.
Status
vulnerable

Advanced Shipment Tracking for WooCommerce # CVE-2021-4347

CVE, Research URL

CVE-2021-4347

Date
Jun 07, 2023
Research Description
The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.
Affected versions
max 3.2.7.
Status
vulnerable
Jun 16, 2026

Advanced Shipment Tracking for WooCommerce # 655be98507ab7cd0e9f95a8ae2b65f2942c7da11

Date
Jul 26, 2021
Research Description
Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] < 3.2.7 Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.
Affected versions
max 3.2.7.
Status
vulnerable
Jul 09, 2026

Advanced Shipment Tracking for WooCommerce # CVE-2026-57773

CVE, Research URL

CVE-2026-57773

Date
-
Research Description
Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] < 4.0.1 CVE-2026-57773
Affected versions
max 4.0.1.
Status
vulnerable