Junglewise Threat Intelligence

CVE-2026-39540: Shipment Tracker for Woocommerce Subscriber XSS

CVE-2026-39540 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Vendors: Unknown.

Executive brief

The Shipment Tracker for Woocommerce plugin for WordPress is vulnerable to a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. This plugin is typically used by e-commerce sites to provide customers with tracking information for their orders. If exploited, an attacker could redirect visitors to malicious websites, steal session information, or display unauthorized advertisements, potentially damaging the site's reputation and compromising customer data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Shipment Tracker for Woocommerce plugin for WordPress due to improper neutralization of user-supplied input (CWE-79). The flaw allows an authenticated attacker with 'Subscriber' level privileges to inject malicious scripts into web pages. Successful exploitation requires a privileged user (such as an administrator) to interact with the affected page or perform a specific action. This can lead to the execution of arbitrary JavaScript in the context of the victim's browser, potentially resulting in session hijacking or site defacement. The issue is addressed in version 1.5.3.3.

Affected products

  • Unknown Shipment Tracker for Woocommerce <= 1.5.3.2

Timeline

  • 2026-01-26: other: Reported by Nguyen Ba Khanh
  • 2026-04-16: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-04-16: patched: Version 1.5.3.3 released to address the vulnerability

References