Junglewise Threat Intelligence

CVE-2026-39602: Rustaurius Order Tracking missing authorization in order-tracking

CVE-2026-39602 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: Etoile Web Design.

Executive brief

The Order Tracking plugin for WordPress, which allows customers to track the status of their orders, contains a security flaw in its access control settings. An unauthorized user could potentially bypass security levels to perform actions they should not be allowed to do, such as modifying order information. This could lead to data integrity issues and disruption of customer service operations.

Technical details

A Broken Access Control vulnerability (CWE-862) exists in the Rustaurius Order Tracking plugin (order-tracking) for WordPress through version 3.4.3. The flaw stems from missing authorization checks or incorrectly configured security levels within the plugin's order-tracking functions. An unauthenticated remote attacker can exploit this vulnerability to execute actions that should be restricted to higher-privileged users. While the CVSS score indicates a partial impact on integrity, the vulnerability allows for unauthorized manipulation of plugin-managed data. No official patch was noted in the primary advisory, though users are advised to monitor for updates beyond version 3.4.3.

Affected products

  • Rustaurius (Etoile Web Design) Order Tracking <= 3.4.3

Timeline

  • 2026-01-01: other: Vulnerability reported by researcher Jakub Herman
  • 2026-01-31: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References