Vulnerabilities / Order Tracking / WPSEC-2026-0560

Order Tracking <= 3.5.4 - Unauthenticated Email Verification Bypass to Order Customer Note Update

Low 3.7 CWE-862Fixed in 3.6.0
ID
WPSEC-2026-0560
Plugin
Order Tracking – WordPress Status Tracking Plugin (order-tracking)
Affected
all versions before 3.6.0
Remediation
Update to 3.6.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Order Tracking on WPSec AttackSurface
Fix released
Published

Description

The Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 3.5.4 due to the ewd_otp_update_customer_note AJAX action not applying the email verification that the plugin enforces when displaying an order. This makes it possible for unauthenticated attackers who know an order's tracking number to overwrite that order's customer notes on sites where email verification is enabled.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0