PT-2024-28822 · WordPress · Orders Tracking For Woocommerce
Matthew Rollings
+1
·
Published
2024-05-10
·
Updated
2024-05-14
·
CVE-2024-4039
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Orders Tracking for WooCommerce plugin for WordPress versions up to 1.2.10
Description
The issue allows unauthenticated attackers to execute arbitrary shortcodes due to the plugin not properly validating a value before running do shortcode. This enables the execution of an action that can lead to arbitrary shortcode execution.
Recommendations
For versions up to 1.2.10, update to version 1.2.11 to fully resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality until the update can be applied.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orders Tracking For Woocommerce