{
 "id": "WPSEC-2026-0563",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0563/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0563/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0563/index.md",
 "title": "Order Tracking <= 3.5.4 - Unauthenticated Email Verification Bypass for Records Without an Email Address",
 "description": "The Order Tracking plugin for WordPress is vulnerable to an authentication bypass of its email verification feature in all versions up to, and including, 3.5.4 due to the order, customer and sales representative email checks treating an empty submitted address as matching an empty stored address. This makes it possible for unauthenticated attackers to view the details and status history of orders, and the order lists of customers and sales representatives, that have no email address stored, on sites where email verification is enabled.",
 "plugin": {
  "slug": "order-tracking",
  "name": "Order Tracking",
  "full_name": "Order Tracking – WordPress Status Tracking Plugin",
  "wordpress_org": "https://wordpress.org/plugins/order-tracking/",
  "advisories_url": "https://wpsec.com/vuln/plugin/order-tracking/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/order-tracking"
 },
 "type": "AUTH",
 "cwe": [
  "CWE-287"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.6.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.6.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.6.0",
 "remediation": "Update to 3.6.0 or later.",
 "fix_released": "2026-10-05T15:28:19+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-07T15:30:55.999728+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0563/",
  "https://plugins.svn.wordpress.org/order-tracking/tags/3.6.0/",
  "https://wordpress.org/plugins/order-tracking/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/order-tracking",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}