Executive brief
A vulnerability exists in the Cargo Shipping Location plugin for WooCommerce, which is used to manage shipping logistics on WordPress e-commerce sites. An attacker can exploit this flaw to gain unauthorized access to the website's database, potentially leading to the theft of sensitive customer information or business data. This issue is considered critical because it can be exploited remotely without needing any login credentials.
Technical details
The Cargo Shipping Location for WooCommerce plugin (versions up to and including 5.6) is vulnerable to a Blind SQL Injection due to improper neutralization of special elements in SQL commands. The vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL queries against the WordPress database. By leveraging blind injection techniques, an attacker can extract sensitive data such as user credentials, configuration details, and customer records. The issue is resolved in version 5.7.
Affected products
- Cargo RD Cargo Shipping Location for WooCommerce n/a through 5.6
Timeline
- 2026-04-01: other: Reported by researcher Benedictus Jovan
- 2026-06-17: advisory: Published by Patchstack and NVD
- 2026-06-17: patched: Fixed in version 5.7