Vulnerabilities / Order Tracking
Order Tracking vulnerabilities
Advisories WPSec published for Order Tracking – WordPress Status Tracking Plugin. Other sources may list more. Its attack surface: Order Tracking on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-07 | WPSEC-2026-0563 | Order Tracking <= 3.5.4 - Unauthenticated Email Verification Bypass for Records Without an Email Address | Low 3.7 | 3.6.0 |
| 2026-10-07 | WPSEC-2026-0562 | Order Tracking <= 3.5.4 - Unauthenticated Payment Bypass via PayPal IPN | Medium 5.3 | 3.6.0 |
| 2026-10-07 | WPSEC-2026-0561 | Order Tracking <= 3.5.4 - Cross-Site Request Forgery to Order Bulk Actions | Medium 5.4 | 3.6.0 |
| 2026-10-07 | WPSEC-2026-0560 | Order Tracking <= 3.5.4 - Unauthenticated Email Verification Bypass to Order Customer Note Update | Low 3.7 | 3.6.0 |
| 2026-10-07 | WPSEC-2026-0559 | Order Tracking <= 3.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Order Viewing and Modification | Medium 5.4 | 3.6.0 |
| 2026-10-07 | WPSEC-2026-0558 | Order Tracking <= 3.5.4 - Unauthenticated Sensitive Information Exposure via Front-End Order Download | Medium 5.9 | 3.6.0 |
License: CC BY 4.0