# Order Tracking <= 3.5.4 - Unauthenticated Email Verification Bypass to Order Customer Note Update

- **ID:** WPSEC-2026-0560
- **Plugin:** Order Tracking – WordPress Status Tracking Plugin (`order-tracking`), https://wordpress.org/plugins/order-tracking/
- **Affected versions:** all versions before 3.6.0
- **Fixed in:** 3.6.0 (Update to 3.6.0 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/order-tracking
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0560/

## Description

The Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 3.5.4 due to the ewd_otp_update_customer_note AJAX action not applying the email verification that the plugin enforces when displaying an order. This makes it possible for unauthenticated attackers who know an order's tracking number to overwrite that order's customer notes on sites where email verification is enabled.

## References

- https://wpsec.com/vuln/WPSEC-2026-0560/
- https://plugins.svn.wordpress.org/order-tracking/tags/3.6.0/
- https://wordpress.org/plugins/order-tracking/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0560/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
