Vulnerabilities / Order Tracking / WPSEC-2026-0559

Order Tracking <= 3.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Order Viewing and Modification

Medium 5.4 CWE-639Fixed in 3.6.0
ID
WPSEC-2026-0559
Plugin
Order Tracking – WordPress Status Tracking Plugin (order-tracking)
Affected
from 3.0.0 before 3.6.0
Remediation
Update to 3.6.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Order Tracking on WPSec AttackSurface
Fix released
Published

Description

The Order Tracking plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 3.0.0 up to, and including, 3.5.4 due to the add/edit order admin page only verifying that the current user is linked to a sales representative, without verifying that the requested order is assigned to that representative. This makes it possible for authenticated attackers with Subscriber-level access and above, whose account is linked to a sales representative, to view and modify any order and delete status history entries of any order.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0