PT-2024-28822 · WordPress · Orders Tracking For Woocommerce

Matthew Rollings

+1

·

Published

2024-05-10

·

Updated

2024-05-14

·

CVE-2024-4039

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Orders Tracking for WooCommerce plugin for WordPress versions up to 1.2.10
Description The issue allows unauthenticated attackers to execute arbitrary shortcodes due to the plugin not properly validating a value before running do shortcode. This enables the execution of an action that can lead to arbitrary shortcode execution.
Recommendations For versions up to 1.2.10, update to version 1.2.11 to fully resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality until the update can be applied.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-4039

Affected Products

Orders Tracking For Woocommerce