Order Tracking – WordPress Status Tracking Plugin, CVE-2026-39602
- CVE, Research URL
- Published on
- Apr 08, 2026
- Research Description
- Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.
- Affected versions
-
max 3.4.3.
- Status
-
vulnerable