Vulnerabilities and security researches forwoo-advanced-shipment-tracking woo-advanced-shipment-tracking
Direction: ascendingJun 06, 2024
Advanced Shipment Tracking for WooCommerce # 5c90d0bbe8b27c274e81eac21e249c973385c7c1
- CVE, Research URL
- Application
- Date
- Jul 26, 2021
- Research Description
- Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] < 3.2.7 WordPress Advanced Shipment Tracking for WooCommerce plugin <= 3.2.6 - Authenticated WordPress Options Change vulnerability Authenticated WordPress Options Change vulnerability discovered by Jerome Bruandet in WordPress Advanced Shipment Tracking for WooCommerce plugin (versions <= 3.2.6).
- Affected versions
-
max 3.2.7.
- Status
-
vulnerable
Advanced Shipment Tracking for WooCommerce # CVE-2022-41635
- CVE, Research URL
- Application
- Date
- May 25, 2023
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Zorem Advanced Shipment Tracking for WooCommerce plugin <= 3.5.2 versions.
- Affected versions
-
max 3.5.3.
- Status
-
vulnerable
Advanced Shipment Tracking for WooCommerce # CVE-2021-4347
- CVE, Research URL
- Application
- Date
- Jun 07, 2023
- Research Description
- The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.
- Affected versions
-
max 3.2.7.
- Status
-
vulnerable
Jun 16, 2026
Advanced Shipment Tracking for WooCommerce # 655be98507ab7cd0e9f95a8ae2b65f2942c7da11
- CVE, Research URL
- Application
- Date
- Jul 26, 2021
- Research Description
- Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] < 3.2.7 Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.
- Affected versions
-
max 3.2.7.
- Status
-
vulnerable
Jul 09, 2026
Advanced Shipment Tracking for WooCommerce # CVE-2026-57773
- CVE, Research URL
- Application
- Date
- Jul 13, 2026
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.
- Affected versions
-
max 4.0.1.
- Status
-
vulnerable
Jul 30, 2026
Advanced Shipment Tracking for WooCommerce # 529cf8a4b1a13080ec21448fd23aa92deab91c7a
- CVE, Research URL
- Application
- Date
- Jul 28, 2026
- Research Description
- Advanced Shipment Tracking for WooCommerce [woo-advanced-shipment-tracking] < 3.9.1 Advanced Shipment Tracking for WooCommerce <= 3.9 - Authenticated (Shop Manager+) SQL Injection via 'tracking_provider' Parameter The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the `tracking_provider` parameter of the `POST /wp-json/wc-ast/v3/orders/<order_id>/shipment-trackings` REST endpoint in all versions up to, and including, 3.9. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in `WC_Advanced_Shipment_Tracking_Admin::get_provider_slug_from_name()` — the value is concatenated directly into the format string of `$wpdb->prepare()` rather than bound as a parameter, bypassing parameterised-query protections. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to append additional SQL queries into the already-existing query that can be used to extract sensitive information from the database.
- Affected versions
-
max 3.9.1.
- Status
-
vulnerable